Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Vulnerability included in the current lodash version used in the repo #25

Open
sfc-gh-jfan opened this issue Aug 27, 2021 · 0 comments

Comments

@sfc-gh-jfan
Copy link

Hey, team. good afternoon!
Our security vulnerability tool whitesource has reported one security vulnerability included in your code:

Path to dependency file: /.github/actions/gajira-close/package.json
Vulnerable Version: lodash-4.17.20.tgz
Reported CVE:
CVE-2020-28500
CVE-2021-23337

Fix version: 4.17.21
Would you mind taking a look? thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant