You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We are using PM2 in our project and we're getting security vulnerability warnings for Lodash versions prior to 4.17.21. Here are the CVEs: CVE-2021-23337 & CVE-2020-28500.
Looks like vizion is using an older version of async (2.6.3) which is throwing the warnings. async has had a major version bump since (releases), which should have squashed the vulnerability.
Could the maintainers update vizion, so in turn PM2 can also update. Thanks! 🙇
The text was updated successfully, but these errors were encountered:
jcass8695
changed the title
Dependency on insecure Lodash version
Dependency on insecure Lodash version 4.17.19
Apr 8, 2021
Hey 👋
We are using PM2 in our project and we're getting security vulnerability warnings for Lodash versions prior to 4.17.21. Here are the CVEs: CVE-2021-23337 & CVE-2020-28500.
Looks like vizion is using an older version of async (2.6.3) which is throwing the warnings. async has had a major version bump since (releases), which should have squashed the vulnerability.
Could the maintainers update vizion, so in turn PM2 can also update. Thanks! 🙇
The text was updated successfully, but these errors were encountered: