fix: pin secure lodash runtime dependency (#44)
This commit is contained in:
1 parent
6bffb98303
commit
7e9a47c949
3 files changed
+16
-3
No files matched your search
Generated
+4
-3
@@ -25,6 +25,7 @@
|
||||
"koa-compress": "^5.2.1",
|
||||
"langdetect": "^0.2.1",
|
||||
"linkedom": "^0.18.12",
|
||||
"lodash": "^4.18.1",
|
||||
"lru-cache": "^11.2.7",
|
||||
"maxmind": "^4.3.29",
|
||||
"minio": "^8.0.7",
|
||||
@@ -4750,9 +4751,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/lodash": {
|
||||
"version": "4.17.23",
|
||||
"resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz",
|
||||
"integrity": "sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==",
|
||||
"version": "4.18.1",
|
||||
"resolved": "https://registry.npmjs.org/lodash/-/lodash-4.18.1.tgz",
|
||||
"integrity": "sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q==",
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/lodash.merge": {
|
||||
|
||||
@@ -39,6 +39,7 @@
|
||||
"koa-compress": "^5.2.1",
|
||||
"langdetect": "^0.2.1",
|
||||
"linkedom": "^0.18.12",
|
||||
"lodash": "^4.18.1",
|
||||
"lru-cache": "^11.2.7",
|
||||
"maxmind": "^4.3.29",
|
||||
"minio": "^8.0.7",
|
||||
|
||||
@@ -44,3 +44,14 @@ test("security baseline file is present and ready for future exceptions", () =>
|
||||
assert.ok(Array.isArray(baseline.entries));
|
||||
assert.equal(baseline.entries.length, 0);
|
||||
});
|
||||
|
||||
test("lodash is declared directly and lockfile avoids the vulnerable 4.17.23 release", () => {
|
||||
const packageJson = JSON.parse(read("package.json"));
|
||||
const packageLock = read("package-lock.json");
|
||||
|
||||
assert.equal(packageJson.dependencies.lodash, "^4.18.1");
|
||||
assert.doesNotMatch(
|
||||
packageLock,
|
||||
/"node_modules\/lodash":\s*\{[\s\S]*?"version":\s*"4\.17\.23"/,
|
||||
);
|
||||
});
|
||||
Reference in new issue
Block a user