SEC-142
High: update lodash 4.17.15 to 4.18.0 (6 vulnerabilities)
- The problem
- lodash 4.17.15 has 6 known vulnerabilities. Version 4.18.0 fixes all of them.
- Where
- acme/web · package-lock.json
- How to fix it
- npm install lodash@4.18.0
- Due date
- Oct 30, from your security policy
Verified as fixed by Pitangus in scan 9f3c… on Oct 2.