Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider stopping using lodash? #272

Closed
s100 opened this issue Jun 26, 2020 · 1 comment
Closed

Consider stopping using lodash? #272

s100 opened this issue Jun 26, 2020 · 1 comment
Labels

Comments

@s100
Copy link

s100 commented Jun 26, 2020

There is a prototype pollution vulnerability in lodash, which lodash's maintainers seem not to be acting on. My suggestion is that moving away from lodash entirely might be an expedient way to resolve this.

Related, previously: #5, #171

@s100 s100 added the question label Jun 26, 2020
@panva
Copy link
Owner

panva commented Jun 26, 2020

openid-client does not utilize the method in question and is therefore not affected. Nevertheless, removing lodash is something I’d support driving a PR forward for if you’re offering putting the time into it.

@panva panva closed this as completed Jun 26, 2020
panva added a commit that referenced this issue Jun 26, 2020
panva added a commit that referenced this issue Jun 26, 2020
@github-actions github-actions bot locked and limited conversation to collaborators Sep 25, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

2 participants