Update lodash to 5.17.11 to resolve node vulnerability audit#579
Update lodash to 5.17.11 to resolve node vulnerability audit#579joeyjmorales wants to merge 1 commit intoswagger-api:masterfrom
Conversation
|
Why this is not merged?? |
|
@WebbizAdmin tests fail |
|
#570 might be relevant. According to that, work is happening to bring the project back to life, so things like the failing Travis and these PRs might get addressed. |
Two can not be fixed yet: - swagger-api/swagger-node#579 - nodejs/node-gyp#1718
|
This is a very tiny PR that could help users of this package stay secure. I use this Maintainers, if the various audit security errors were patched and a very small maintenance release were pushed I think existing users would greatly appreciate it. (I know I would!) (Incidentally PR name is slightly off, the major version for |
|
Actually this PR isn't strictly necessary. On That means "greater than (or equal to) 4.17.2, but also less than 5.x" If there were a new release of this package based off of the The fix that would be more meaningful would be for there to be a new release of this package. |
No description provided.