Skip to content

Comments

Update package.json#1873

Draft
RamyaPayyavula wants to merge 1 commit intoimport-js:mainfrom
RamyaPayyavula:patch-1
Draft

Update package.json#1873
RamyaPayyavula wants to merge 1 commit intoimport-js:mainfrom
RamyaPayyavula:patch-1

Conversation

@RamyaPayyavula
Copy link

older version of babel brings lodash vulnerabilities

older version of babel brings lodash vulnerabilities
Copy link
Member

@ljharb ljharb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Upgrading from babel 6 to 7 is a major change, that we're not prepared to make; in addition, these "lodash vulnerabilities" aren't actually a problem, both overall or for how babel uses lodash. Most audit warnings these days are false positives and don't need corrective action.

@ljharb ljharb marked this pull request as draft February 1, 2021 18:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

3 participants