robinvdvleuten/shvl

High Severity: Prototype Pollution in vulnerable module shvl@2.0.1

Closed this issue · 1 comments

  • shvl version: 2.0.1
  • node version: 12.6.1
  • npm (or yarn) version: 6.13.4

Problem description:
Snyk reported recently about High Severity: Prototype Pollution in vulnerable module shvl@2.0.1 . The vuex-persistedstate project depends on shvl and therefore became listed as vulnerable primary dependency in our production project.
https://snyk.io/test/npm/shvl/2.0.1

Could you have a look and provide fix please?

I probably can, but what should be the fix?