serkanyersen/jsonplus

Lodash Vulnerability

Opened this issue · 0 comments

There are multiple advisories issued for the version of Lodash declared as a dependency here.

https://nvd.nist.gov/vuln/detail/CVE-2019-10744

It is advised to upgrade to Lodash > 4.17.12.

Do you plan on releasing a patch or an upgrade to address this?