Skip to content

Critical security vulnerability #60

@skhilliard

Description

@skhilliard

gulp-run has a dependency on gulp-util which references a version of lodash.template that has a critical vulnerability. Would it be possible to update gulp-run to eliminate this? Unfortunately, I see that the gulp-util project has been deprecated.

gulp-run > gulp-util > lodash.template
GHSA-jf85-cpcp-j695

`-- gulp-run@1.7.1
  +-- gulp-util@3.0.8
  | `-- lodash.template@3.6.2
  `-- lodash.template@4.5.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions