Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings
This repository was archived by the owner on Sep 16, 2023. It is now read-only.

Update package.json #172

Open
RamyaPayyavula wants to merge 1 commit into lodash:master
base: master
Choose a base branch
Loading
from RamyaPayyavula:patch-1
Open

Conversation

@RamyaPayyavula
Copy link

@RamyaPayyavula RamyaPayyavula commented Aug 7, 2020

older version of babel and lodash has injection vulnerability. An attacker can inject malicious code via sourceURL since it is not sanitized for the user-provided code that leads to the eval() function.

older version of babel and lodash has injection vulnerability. An attacker can inject malicious code via `sourceURL` since it is not sanitized for the user-provided code that leads to the `eval()` function.
Copy link

CLA assistant check
Thank you for your submission, we really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.

Copy link

Hi @RamyaPayyavula!

See #171 😃

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Reviewers

No reviews

Assignees

No one assigned

Labels

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

AltStyle によって変換されたページ (->オリジナル) /