Open
Description
Thank you for your package. I have included it my projekt httpyac, but now I also get npm audit
errors. There is a CVE in lodash.set. Could you possibly switch to an alternative like lodash
or lodash-es
to fix this?
lodash.set *
Severity: high
Prototype Pollution in lodash - https://github.com/advisories/GHSA-p6mc-m468-83gw
No fix available
node_modules/lodash.set
grpc-reflection-js *
Depends on vulnerable versions of lodash.set
node_modules/grpc-reflection-js
2 high severity vulnerabilities
Metadata
Metadata
Assignees
Labels
No labels