Hi,
My scanner is picking up a vulnerability from underscore It appears the issue is that underscore is using a lodash script in underscore-min.js. Is that correct? Can anyone confirm?
There was a PR that fixed the issue in 4.17.21.
https://github.com/lodash/lodash/pull/5085/files