Skip to content

Removing lodash.template depency as per the component Governance Alert#36

Open
BrahminiPaleti wants to merge 1 commit intoDragory:masterfrom
BrahminiPaleti:dev/GulpHashLodashTemplateRemovalChanges
Open

Removing lodash.template depency as per the component Governance Alert#36
BrahminiPaleti wants to merge 1 commit intoDragory:masterfrom
BrahminiPaleti:dev/GulpHashLodashTemplateRemovalChanges

Conversation

@BrahminiPaleti
Copy link
Copy Markdown

As per the component governance alert made changes to remove lodash.template and replace with lodash. Made the fix as per the suggestion provided in below link.

lodash/lodash#5851

"If you are using lodash.template directly in a project, to remove this alert you should install the latest version of lodash and use the template method off the main Lodash module instead, if you can't use another approach entirely."

@tlatin
Copy link
Copy Markdown

tlatin commented Nov 19, 2024

This address CVE-2021-23337, an open security issue with using lodash.template. Also lodash.template is considered unowned and unsupported at this point.

When can this get reviewed?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants