Skip to content
This repository has been archived by the owner on Oct 6, 2020. It is now read-only.

Security vulnerability from locked Hoek and Lodash versions #10

Open
cefn opened this issue Oct 1, 2018 · 1 comment
Open

Security vulnerability from locked Hoek and Lodash versions #10

cefn opened this issue Oct 1, 2018 · 1 comment

Comments

@cefn
Copy link

cefn commented Oct 1, 2018

As described here...

https://nodesecurity.io/check/request-http-cache

...locking to major versions lodash:3.x.x and wreck:5.x.x in https://github.com/gitterHQ/request-http-cache/blob/master/package.json means request-http-cache is locked into modules which have known security issues.

Distributing a new version of request-http-cache with a version bump to the latest lodash and wreck should address this.

cbsorrilha added a commit to cbsorrilha/request-http-cache that referenced this issue Oct 7, 2018
@altany
Copy link

altany commented Dec 20, 2019

Can this be updated please? It is causing a security vulnerability to my repo.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants