Skip to content

High vulnerability from set-value #261

@TheoMugnier

Description

@TheoMugnier

🚫Pinning group array to 0.3.3 lead to a high vulnerability ! 🚫
So this can't be considered a permanent fix (Fixed in 0.3.4 of group-array)
(Merged PR: #258)

From npm audit security report :

High : Prototype Pollution
Package : set-value
Patched in : >=2.0.1 <3.0.0 || >=3.0.1
Dependency of : gulp-inject
Path : gulp-inject > group-array > union-value > set-value
More info : https://npmjs.com/advisories/1012

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions