Skip to content

Update lodash due to security#14

Merged
analog-nico merged 1 commit into
request:masterfrom
Alec321:patch-1
Feb 14, 2019
Merged

Update lodash due to security#14
analog-nico merged 1 commit into
request:masterfrom
Alec321:patch-1

Conversation

@Alec321

@Alec321 Alec321 commented Feb 12, 2019

Copy link
Copy Markdown
Contributor

Prior versions of lodash have been compromised so you should force users to grab 4.17.11
All tests seem to still run locally.

Prior versions of lodash have been compromised so you should force users to grab 4.17.11
@coveralls

Copy link
Copy Markdown

Coverage Status

Coverage remained the same at 100.0% when pulling c837026 on Alec321:patch-1 into 77e4f18 on request:master.

@CorWatts

Copy link
Copy Markdown

Instead of this, could we merge in #7 and update the lodash deps there?

@Alec321

Alec321 commented Feb 13, 2019

Copy link
Copy Markdown
Contributor Author

@CorWatts You could, however, it looks like #7 removes the dependency and depends on submodules of lodash. It shouldn't hurt merging this in then merging in the #7 .

@analog-nico analog-nico merged commit c61e41f into request:master Feb 14, 2019
@analog-nico

Copy link
Copy Markdown
Member

Thanks a lot @Alec321 ! @CorWatts I will take care of your PR as well.

@analog-nico

Copy link
Copy Markdown
Member

I just released request-promise@4.2.3, request-promise-native@1.0.6, and request-promise-any@1.0.6 which include this fix.

@Alec321

Alec321 commented Feb 15, 2019

Copy link
Copy Markdown
Contributor Author

Thank you!

@analog-nico

Copy link
Copy Markdown
Member

Cheers @Alec321 ! :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants