jantimon/html-webpack-plugin

Prototype Pollution and Command Injection in lodash as High Risk

cherrelleM1 opened this issue ยท 1 comments

Current behaviour ๐Ÿ’ฃ

The Github Dependabot alerts cannot update lodash package.
GHSA-p6mc-m468-83gw

Expected behaviour โ˜€๏ธ

The Github Dependabot alerts should be able to update.

Reproduction Example ๐Ÿ‘พ

On github, go to security tab.
image

image

Environment ๐Ÿ–ฅ

Node.js v16.13.2
win32 10.0.18363
8.3.2

"html-webpack-plugin": "^5.5.0",

Fixed on lodash side, please update your deps, sorry for a logn answer