Skip to content

Fixing prototype Pollution in lodash.pick#5799

Open
hdsenevi wants to merge 1 commit into
GeekyAnts:masterfrom
hdsenevi:fix/vulnerability-GHSA-p6mc-m468-83gw
Open

Fixing prototype Pollution in lodash.pick#5799
hdsenevi wants to merge 1 commit into
GeekyAnts:masterfrom
hdsenevi:fix/vulnerability-GHSA-p6mc-m468-83gw

Conversation

@hdsenevi

@hdsenevi hdsenevi commented Jan 29, 2024

Copy link
Copy Markdown

Summary

  • Fixing prototype Pollution in lodash.pick
  • Removed usage of lodash.pick and replaced with lodash proper
  • Github advisory info here : GHSA-p6mc-m468-83gw

Also, lodash discourages per module packages (additional info here). So maybe we can get rid of all the per module packages and import only lodash

Changelog

[CATEGORY] [TYPE] - Message

Test Plan

@auto-assign auto-assign Bot requested a review from rayan1810 January 29, 2024 05:41
@vercel

vercel Bot commented Jan 29, 2024

Copy link
Copy Markdown

@hdsenevi is attempting to deploy a commit to the Geekyants Team Team on Vercel.

A member of the Team first needs to authorize it.

@hdsenevi hdsenevi changed the title Removed usage of lodash.pick and replaced with lodash proper Fixing prototype Pollution in lodash.pick Jan 29, 2024
@ifero

ifero commented Jun 19, 2024

Copy link
Copy Markdown

Is there any ETA on merging this? This is causing several issues to our deployments

@heg2

heg2 commented Aug 20, 2024

Copy link
Copy Markdown

We would also highly appreciate if you could merge this PR @rayan1810.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants