[Security] Lodash vulnerability
envgap__kulshekhar__ts-jest-4316
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
e882a827ed588dfcb0b602e9925a96a139087eb8- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
kulshekhar/ts-jest #4316 · read the original issue
This library depends on vulnerable versions of lodash Here is the detailed information - https://github.com/advisories/GHSA-35jh-r3h4-6jhm Currently this library uses lodash which should be updated library version : 6.1.3 Environment : Mac OS Example URL : https://github.com/advisories/GHSA-35jh-r3h4-6jhm Other libraries you are using: NA What did you expect to happen? Lodash version to be >= 4.17.21 What actually happens Lodash has vulnerable versions How to reproduce Navigate to package.json and look for lodash version
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]