-
Notifications
You must be signed in to change notification settings - Fork 6
Closed
Labels
securityThis issue concerns a security vulnerabilityThis issue concerns a security vulnerability
Description
Snyk identified an security vulnerability in an upstream dependency of [email protected], as noted by other users here: FormidableLabs/measure-text#5.
Prototype Pollution
- Vulnerable module: lodash.merge
- Introduced through: [email protected]
- Path: [email protected] › [email protected] › [email protected]
- CVE-2018-3721
The issue is still outstanding, so in the interim I will import the measure-text dependent code into the react-middle-truncate repo until this issue is resolved.
Metadata
Metadata
Assignees
Labels
securityThis issue concerns a security vulnerabilityThis issue concerns a security vulnerability