dthree / vorpal

Node's framework for interactive CLIs

Home Page:http://vorpal.js.org

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Node Security Issue with lodash: 577 - Prototype Pollution

johncblandii opened this issue · comments

screen shot 2018-05-14 at 6 04 49 pm

We need a lodash update. It'd be a good time to release to resolve #301 as well.

I can approve this. +1

It still seems to be a problem on 1.12.0 according to Snyk (https://app.snyk.io/test/npm/vorpal/1.12.0).

I'm pretty sure this project is dead, @Berkmann18.

Why has this not been merged, rather unacceptable that a high security vulnerability has been here for over a year

@tsujp Because the project is dead and the old vorpal admins haven’t put anyone else in charge.

I'm starting using this fork: npm i @moleculer/vorpal