sendgrid / nodemailer-sendgrid-transport

SendGrid transport for Nodemailer
MIT License
116 stars 61 forks source link

Lodash Dependency is outdated High Prototype Pollution Vulnerability #74

Open d0rf47 opened 4 years ago

d0rf47 commented 4 years ago

I am using sengrid in an project and npm audit shows some high vulnerability security issues. With your Lodash dependency. High Prototype Pollution

Package lodash

Patched in >=4.17.11

Dependency of nodemailer-sendgrid-transport

Path nodemailer-sendgrid-transport > sendgrid > lodash

More info https://npmjs.com/advisories/782

High Prototype Pollution

Package lodash

Patched in >=4.17.12

Dependency of nodemailer-sendgrid-transport

Path nodemailer-sendgrid-transport > sendgrid > lodash

Is there a way to manually fix this on my end or do I need to do a pull request as suggested by npm

tubbo commented 3 years ago

also having this issue if anyone's around to bump the dependency?

Dunsin-cyber commented 1 year ago

any solution? or way around?