-
Notifications
You must be signed in to change notification settings - Fork 22
Open
Description
gulp-run has a dependency on gulp-util which references a version of lodash.template that has a critical vulnerability. Would it be possible to update gulp-run to eliminate this? Unfortunately, I see that the gulp-util project has been deprecated.
gulp-run > gulp-util > lodash.template
GHSA-jf85-cpcp-j695
`-- gulp-run@1.7.1
+-- gulp-util@3.0.8
| `-- lodash.template@3.6.2
`-- lodash.template@4.5.0
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels