âââââââââââââââââ¬âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
â Low â Prototype Pollution â
âââââââââââââââââ¼âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ¤
â Package â lodash â
âââââââââââââââââ¼âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ¤
â Patched in â >=4.17.5 â
âââââââââââââââââ¼âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ¤
â Dependency of â react-native-cached-image â
âââââââââââââââââ¼âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ¤
â Path â react-native-cached-image > lodash â
âââââââââââââââââ¼âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ¤
â More info â https://npmjs.com/advisories/577 â
âââââââââââââââââ´âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
found 11 vulnerabilities (2 low, 8 moderate, 1 high) in 26316 scanned packages
11 vulnerabilities require manual review. See the full report for details.
当我试图
npm install
,所有这些都需要手动审查。我试着去拜访
this
去查更多的信息显然是因为
lodash
是版本的
4.17.4
. 所以我就跑
npm install --save lodash@4.17.5
并检查了我的
package.json
以确保它的反射正确。
然而,这些漏洞似乎仍然存在。不知道我是不是弄错了?
根据请求,package.json的主体
"dependencies": {
"lodash": "^4.17.5",
}