← All tasks
javascriptkulshekhar/ts-jest #4316Not a task: already works

[Security] Lodash vulnerability

envgap__kulshekhar__ts-jest-4316

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
e882a827ed588dfcb0b602e9925a96a139087eb8
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

kulshekhar/ts-jest #4316 · read the original issue
This library depends on vulnerable versions of lodash

Here is the detailed information - https://github.com/advisories/GHSA-35jh-r3h4-6jhm



Currently this library uses lodash  which should be updated



library version : 6.1.3

Environment : Mac OS

Example URL : https://github.com/advisories/GHSA-35jh-r3h4-6jhm

Other libraries you are using: NA

What did you expect to happen?

Lodash version to be >= 4.17.21



What actually happens

Lodash has vulnerable versions



How to reproduce

Navigate to package.json and look for lodash version
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]