Commit 4d113d2
committed
Update vulnerable dependencies
- Bump lodash-es 4.17.21 -> 4.18.1 (runtime dependency; fixes the
_.template code injection and _.unset/_.omit prototype pollution
advisories)
- Refresh package-lock.json to pull patched versions of vulnerable
transitive dependencies within their existing ranges: ws 8.21.1 via
engine.io/socket.io updates, node-forge 1.4.0, lodash 4.18.1,
immutable 3.8.3, qs 6.5.5, path-to-regexp 1.9.0, send/serve-static,
eazy-logger, cookie, braces, follow-redirects, micromatch,
cross-spawn, ajv, js-yaml, yaml, picomatch, and related chains1 parent c3f224b commit 4d113d2
2 files changed
Lines changed: 724 additions & 362 deletions
0 commit comments