Open d0rf47 opened 4 years ago
I am using sengrid in an project and npm audit shows some high vulnerability security issues. With your Lodash dependency. High Prototype Pollution
Package lodash
Patched in >=4.17.11
Dependency of nodemailer-sendgrid-transport
Path nodemailer-sendgrid-transport > sendgrid > lodash
More info https://npmjs.com/advisories/782
High Prototype Pollution
Patched in >=4.17.12
Is there a way to manually fix this on my end or do I need to do a pull request as suggested by npm
also having this issue if anyone's around to bump the dependency?
any solution? or way around?
I am using sengrid in an project and npm audit shows some high vulnerability security issues. With your Lodash dependency. High Prototype Pollution
Package lodash
Patched in >=4.17.11
Dependency of nodemailer-sendgrid-transport
Path nodemailer-sendgrid-transport > sendgrid > lodash
More info https://npmjs.com/advisories/782
High Prototype Pollution
Package lodash
Patched in >=4.17.12
Dependency of nodemailer-sendgrid-transport
Path nodemailer-sendgrid-transport > sendgrid > lodash
Is there a way to manually fix this on my end or do I need to do a pull request as suggested by npm