Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Cut stable release with upgraded lodash or cli-table3 #200

Closed
mike-north opened this issue Jul 9, 2018 · 2 comments
Closed

Comments

@mike-north
Copy link
Member

mike-north commented Jul 9, 2018

I'm not sure whether 1.0 is nearly ready, but it would be nice to get a stable release cut. Until then, the most recent (0.2.23) will cause npm6 users to get warnings about this low-risk lodash security issue.

https://nodesecurity.io/advisories/577
https://hackerone.com/reports/310443

It may be worth cutting an ember-try v0.3 or something.

Pinning to lodash >=4.17.5 may do the trick, assuming everything else is happy with that version.

@rwjblue
Copy link
Member

rwjblue commented Jul 9, 2018

Agreed. I think we can do both: release a patch version of 0.2 and release 1.0.0.

@kategengler
Copy link
Member

v1.0.0 is released

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants