Skip to content

[Snyk] Security upgrade lodash from 4.17.19 to 4.17.20#788

Merged
ShayNehmad merged 1 commit intodevelopfrom
snyk-fix-98e044718f85188afe45a782f8afeef2
Aug 17, 2020
Merged

[Snyk] Security upgrade lodash from 4.17.19 to 4.17.20#788
ShayNehmad merged 1 commit intodevelopfrom
snyk-fix-98e044718f85188afe45a782f8afeef2

Conversation

@snyk-bot
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • monkey/monkey_island/cc/ui/package.json
    • monkey/monkey_island/cc/ui/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 776/1000
Why? Recently disclosed, Has a fix available, CVSS 9.8
Prototype Pollution
SNYK-JS-LODASH-590103
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

…c/ui/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-590103
@codecov
Copy link

codecov bot commented Aug 17, 2020

Codecov Report

Merging #788 into develop will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@ Coverage Diff @@ ## develop #788 +/- ## ======================================== Coverage 60.32% 60.32% ======================================== Files 161 161 Lines 4900 4900 ======================================== Hits 2956 2956 Misses 1944 1944 

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 9754e1b...7b9079b. Read the comment docs.

@ShayNehmad ShayNehmad self-requested a review August 17, 2020 11:17
@ShayNehmad
Copy link
Contributor

Tested, works

@ShayNehmad ShayNehmad merged commit 4674e60 into develop Aug 17, 2020
@ShayNehmad ShayNehmad deleted the snyk-fix-98e044718f85188afe45a782f8afeef2 branch August 17, 2020 11:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants