Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DepShield] (CVSS 7.4) Vulnerability due to usage of lodash.isstring:4.0.1 #12

Closed
sonatype-depshield bot opened this issue Oct 1, 2019 · 2 comments
Labels
invalid This doesn't seem right vulnerability wontfix This will not be worked on

Comments

@sonatype-depshield
Copy link

Vulnerabilities

DepShield reports that this application's usage of lodash.isstring:4.0.1 results in the following vulnerability(s):


Occurrences

lodash.isstring:4.0.1 is a transitive dependency introduced by the following direct dependency(s):

verdaccio:4.3.0
        └─ jsonwebtoken:8.5.1
              └─ lodash.isstring:4.0.1

This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.

@issue-label-bot issue-label-bot bot added the bug Something isn't working label Oct 1, 2019
@issue-label-bot
Copy link

Issue-Label Bot is automatically applying the label bug to this issue, with a confidence of 0.88. Please mark this comment with 👍 or 👎 to give our bot feedback!

Links: app homepage, dashboard and code for this bot.

@jjangga0214 jjangga0214 added vulnerability wontfix This will not be worked on and removed bug Something isn't working labels Oct 1, 2019
@jjangga0214
Copy link
Owner

Closing this issue as this is a devDependency and unlikely to take an effect.

@jjangga0214 jjangga0214 added the invalid This doesn't seem right label Oct 1, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
invalid This doesn't seem right vulnerability wontfix This will not be worked on
Projects
None yet
Development

No branches or pull requests

1 participant