vuex-persistedstate version: 2.2.0 and all the versions released after that
node version: 12.13.0
npm (or yarn) version: 6.14.7
Problem description:
Snyk had reported High Severity: Prototype Pollution for all the shvl versions released before shvl@2.0.3. The vuex-persistedstate project depends on shvl and therefore became listed as a vulnerable primary dependency in our production project which uses vuex-persistedstate@2.5.4, vue@2.6.10 and vuex@3.1.0. please check below:
https://snyk.io/vuln/npm:shvl
Suggested solution:
The recommended version of shvl that has the fix for High Severity: Prototype Pollution is shvl@2.0.3
https://snyk.io/test/npm/shvl/2.0.3
vuex-persistedstate
version: 2.2.0 and all the versions released after thatnode
version: 12.13.0npm
(oryarn
) version: 6.14.7Problem description: Snyk had reported High Severity: Prototype Pollution for all the shvl versions released before shvl@2.0.3. The vuex-persistedstate project depends on shvl and therefore became listed as a vulnerable primary dependency in our production project which uses vuex-persistedstate@2.5.4, vue@2.6.10 and vuex@3.1.0. please check below: https://snyk.io/vuln/npm:shvl
Suggested solution: The recommended version of shvl that has the fix for High Severity: Prototype Pollution is shvl@2.0.3 https://snyk.io/test/npm/shvl/2.0.3