Skip to content

nested dependency lodash has high vulnerability. Please update >=4.17.21  #16

Description

@ingstartup

nested dependency lodash has high vulnerability. Please update lodash to >=4.17.21 and publish a new react-native-just-timeline when you get a chance.

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High          │ Command Injection                                            │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ lodash                                                       │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=4.17.21                                                    │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ react-native-just-timeline                                   │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ react-native-just-timeline > lodash                          │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://npmjs.com/advisories/1673                            │
└───────────────┴──────────────────────────────────────────────────────────────┘

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions