sendgrid / nodemailer-sendgrid-transport

SendGrid transport for Nodemailer

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Lodash Dependency is outdated High Prototype Pollution Vulnerability

d0rf47 opened this issue · comments

I am using sengrid in an project and npm audit shows some high vulnerability security issues. With your Lodash dependency.
High Prototype Pollution

Package lodash

Patched in >=4.17.11

Dependency of nodemailer-sendgrid-transport

Path nodemailer-sendgrid-transport > sendgrid > lodash

More info https://npmjs.com/advisories/782

High Prototype Pollution

Package lodash

Patched in >=4.17.12

Dependency of nodemailer-sendgrid-transport

Path nodemailer-sendgrid-transport > sendgrid > lodash

Is there a way to manually fix this on my end or do I need to do a pull request as suggested by npm

also having this issue if anyone's around to bump the dependency?

any solution? or way around?