Usage lodash.template dependency version 4.5.0 in grapesjs-cli is having transitive dependency security issue
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 45/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- typescript
Research direction
Start by locating the dependency declarations and lockfile for grapesjs-cli, then trace how lodash.template is introduced transitively. Update the dependency resolution to use lodash 4.17.21 and verify that the resulting dependency tree no longer reports the stated security issue.
Written by the indexing model from the issue text.
Description
We noticed that usage of lodash.template dependency in grapesjs-cli is causing a high security transitive dependency issue.
The following updates should be made:
Usage of lodash versiopn 4.17.21 has fix for the the issue rather than using loash.template
- Dominant language
- TypeScript
- Stars
- 107
- Forks
- 32
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from GrapesJS/cli
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
-
Difficulty 3/5 1-2 days Newbie friendliness 25/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
bcgov/bc-wallet-mobile#4761 · 1 comment ·
-
external-issue to-triage
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
area-deployment area-integrations triage:bot-seen
Difficulty 2/5 Half a day Newbie friendliness 86/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
refactor
Difficulty 2/5 1-3 hours Newbie friendliness 84/100