Skip to content

Lodash Dependency is outdated High Prototype Pollution Vulnerability #74

@d0rf47

Description

@d0rf47

I am using sengrid in an project and npm audit shows some high vulnerability security issues. With your Lodash dependency.
High Prototype Pollution

Package lodash

Patched in >=4.17.11

Dependency of nodemailer-sendgrid-transport

Path nodemailer-sendgrid-transport > sendgrid > lodash

More info https://npmjs.com/advisories/782

High Prototype Pollution

Package lodash

Patched in >=4.17.12

Dependency of nodemailer-sendgrid-transport

Path nodemailer-sendgrid-transport > sendgrid > lodash

Is there a way to manually fix this on my end or do I need to do a pull request as suggested by npm

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions