klei/gulp-inject

High vulnerability: Prototype Pollution in set-value

suhailkc opened this issue · 0 comments

npm audit:

set-value 3.0.0 - 4.0.0
Severity: high
Prototype Pollution in set-value - GHSA-4jqc-8m5r-9rpr
fix available via npm audit fix --force
Will install gulp-inject@5.0.3, which is a breaking change
node_modules/set-value
union-value >=2.0.1
Depends on vulnerable versions of set-value
node_modules/union-value
group-array >=1.0.0
Depends on vulnerable versions of union-value
node_modules/group-array
gulp-inject >=5.0.4
Depends on vulnerable versions of group-array
node_modules/gulp-inject