Friday 26 July 2019

Github can create a PR for security updates to NPM packages

https://help.github.com/en/articles/about-security-alerts-for-vulnerable-dependencies#alerts-and-automated-security-fixes-for-vulnerable-dependencieshttps://i.redd.it/u9q4sihz3pc31.pnghttps://i.redd.it/wf1cfej34pc31.png(not strictly for node, but very handy to know)also, be sure to update your lodash, you definitely have seen the npm audit by now saying how many packages were impactedhttps://snyk.io/blog/snyk-research-team-discovers-severe-prototype-pollution-security-vulnerabilities-affecting-all-versions-of-lodash/

Submitted July 26, 2019 at 08:03PM by bouldermikem

No comments:

Post a Comment