Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Publish latest version of the "lodash.template" package #5738

Closed
alexander-kraev-snyk opened this issue Sep 26, 2023 · 2 comments
Closed

Publish latest version of the "lodash.template" package #5738

alexander-kraev-snyk opened this issue Sep 26, 2023 · 2 comments
Labels

Comments

@alexander-kraev-snyk
Copy link

Latest version of "lodash.template" package was published to npm 4 years ago and now its' outdated (4.5.0)

@jdalton Hello John! How it can be published manually? Can it be done by non-maintainer like me?

NPM link - https://www.npmjs.com/package/lodash.template?activeTab=versions

Please do not close the issue until the matter is resolved

@jdalton
Copy link
Member

jdalton commented Sep 27, 2023

Hi @alexander-kraev-snyk! Ideally folks would move to a logic-less, non-eval based template. If the package has been idle for 4 years I don't see the urgency now in updating it. I'm not at the place in the backlog of tech debt to manually publish updates but have been thinking about the approach. I'll update you when I get to that.

@jdalton jdalton closed this as completed Sep 27, 2023
@gorner
Copy link

gorner commented Apr 18, 2024

Given that a security advisory from 2021 was updated this week to specifically refer to lodash.template as being affected, do you intend to revisit this matter @jdalton? I suspect the new inclusion of lodash.template – which is still a transitive dependency of many other packages – may be causing some developers to panic.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Development

No branches or pull requests

3 participants