yamadapc / jsdoctest

Run jsdoc examples as doctests.
https://yamadapc.github.io/jsdoctest
MIT License
92 stars 9 forks source link

lodash dependency vulnerability - need for rebuild? #38

Open rogalmic opened 4 years ago

rogalmic commented 4 years ago
  Low             Prototype Pollution                                           

  Package         lodash                                                        

  Patched in      >=4.17.5                                                      

  Dependency of   jsdoctest [dev]                                               

  Path            jsdoctest > dox > jsdoctypeparser > lodash                    

  More info       https://nodesecurity.io/advisories/577                        

  High            Prototype Pollution                                           

  Package         lodash                                                        

  Patched in      >=4.17.11                                                     

  Dependency of   jsdoctest [dev]                                               

  Path            jsdoctest > dox > jsdoctypeparser > lodash                    

  More info       https://nodesecurity.io/advisories/782                        

  High            Prototype Pollution                                           

  Package         lodash                                                        

  Patched in      >=4.17.12                                                     

  Dependency of   jsdoctest [dev]                                               

  Path            jsdoctest > dox > jsdoctypeparser > lodash                    

  More info       https://nodesecurity.io/advisories/1065                       

found 3 vulnerabilities (1 low, 2 high) in 1412 scanned packages
  3 vulnerabilities require manual review. See the full report for details.