CVE-2021-23337 Command Injection in lodash #39014
Labels
status: triage needed
Issue or pull request that need to be triaged and assigned to a reviewer
type: bug
An issue or pull request relating to a bug in Gatsby
Preliminary Checks
Description
A dependency of
gatsby-plugin-offline
, namelyworkbox-build
has a dependency calledlodash.template
that has a vulnerability reported: GHSA-35jh-r3h4-6jhmI logged a bug with Google workbook to no avail: GoogleChrome/workbox#3322
Here is a discussion that explains why lodash cannot fix this: lodash/lodash#5851
What could be done to fix this in gatsby?
Reproduction Link
N/A
Steps to Reproduce
This is the result of a GitHub dependabot alert
Expected Result
clear dependabot alert list
Actual Result
dependabot alert
Environment
Config Flags
No response
The text was updated successfully, but these errors were encountered: