Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Lodash in deps have security issue - need to upgrade lodash version #65

Open
deksden opened this issue Mar 13, 2018 · 9 comments
Open

Comments

@deksden
Copy link

deksden commented Mar 13, 2018

More info: https://snyk.io/vuln/npm:lodash:20180130

How to fix: Upgrade lodash to version 4.17.5 or higher.

@thinkingserious
Copy link
Contributor

Thanks for the heads up @deksden!

@Berkmann18
Copy link

Berkmann18 commented Jul 3, 2018

I can confirm the issue and the upgrade to do.
Source: https://nodesecurity.io/advisories/577 (after running a nsp check command on one of my projects).
If no one wants to be assigned to resolving that then I won't mind doing that.

@thinkingserious
Copy link
Contributor

Thanks @Berkmann18!

Berkmann18 added a commit to Berkmann18/nodemailer-sendgrid-transport that referenced this issue Jul 5, 2018
I updated some packages due to a security vulnerability raised in [sendgrid#65](sendgrid#65) and as a follow up to the PR [sendgrid#64](sendgrid#64) (where I added a basic issue template and one use case).
@Berkmann18 Berkmann18 mentioned this issue Jul 5, 2018
6 tasks
Berkmann18 added a commit to Berkmann18/sendgrid-nodejs that referenced this issue Jul 27, 2018
I also refactored some of it such that it contains only the necessary
files, as well as follow the structure that the other sub-packages
follow.

This commit should help with the PRs:
- [NST#67](sendgrid/nodemailer-sendgrid-transport#67)
- [NST#64](sendgrid/nodemailer-sendgrid-transport#64)

And the following issues:
- [NST#65](sendgrid/nodemailer-sendgrid-transport#65)
- [NST#25](sendgrid/nodemailer-sendgrid-transport#25)

The problem I face despit this commit being here is that some
sub-packages require the old `sendgrid` package which works differently
then this one.
@dario-ramos
Copy link

What is missing to complete this? I just completed a Lodash upgrade from 3.x to 4.x, so I can help with that part. I blogged my experience: https://programatealgo.blogspot.com/2019/01/upgrading-lodash-from-3x-to-4x.html

@Berkmann18
Copy link

@dario-ramos This issue should normally be resolved.

@sudhanshugaur4
Copy link

As there is no update added, can anyone please tell me how can I resolve this error.

@Berkmann18
Copy link

@sudhanshugaur4 It is as far as I can tell.
Plus this repo was moved to https://github.com/sendgrid/sendgrid-nodejs.

@proton1k
Copy link

proton1k commented Oct 14, 2020

It seems to me this repo is not maintained anymore. Abandoned city yal' boys... A lonely cowboy only passes by this place...
AFAIK the official repo is now https://github.com/sendgrid/sendgrid-nodejs and you can still work with SMTP directly (link).

@1Luc1
Copy link

1Luc1 commented Jan 6, 2021

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

7 participants