-
Notifications
You must be signed in to change notification settings - Fork 3.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade lodash dependency to fix prototype pollution exploit #4699
Comments
😅 Yes, PR is here #4684 |
When will this fix be released? @jennifer-shehane |
We are still waiting for this to be release right?
|
The code for this is done in #4709, but this has yet to be released. We'll update this issue and reference the changelog when it's released. You can run But also Cypress is immune to most if not all security vulnerabilities because its locally run software - not a web server hosted in the cloud, so this security issue doesn't even apply and is low priority for us. |
@jennifer-shehane it blocking our code from build and deploy since we have role to prevent and deployment with Vulnerability, please merge |
We are working on a patch release now, instead of waiting for feature release. |
Released in |
Thanks for the patch release :) |
EDIT: Apparently this made it into develop in between when I checked this and went to make the issue
The text was updated successfully, but these errors were encountered: