@sailshq/lodash
Advanced tools
Comparing version
{ | ||
"name": "@sailshq/lodash", | ||
"version": "3.10.3", | ||
"version": "3.10.4", | ||
"description": "A fork of Lodash 3.10.x with ongoing maintenance from the Sails core team.", | ||
@@ -5,0 +5,0 @@ "main": "lib/index.js", |
@@ -34,2 +34,3 @@ # @sailshq/lodash | ||
- [Fix prototype polution security vulnerability](https://github.com/lodash/lodash/issues/2768) _(see also JD's comments [here](https://hackerone.com/reports/310443))_ | ||
- [Fix another prototype polution security vulnerability](https://snyk.io/vuln/SNYK-JS-LODASH-73638) | ||
@@ -36,0 +37,0 @@ ## Bugs [](https://badge.fury.io/js/%40sailshq%2Flodash) |
Sorry, the diff of this file is too big to display
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
427319
0.12%11896
0.06%60
1.69%1
Infinity%