Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: snyk ignore lodash #5281

Merged
merged 3 commits into from Jul 5, 2019
Merged

Conversation

spencern
Copy link
Contributor

@spencern spencern commented Jul 5, 2019

Sets snyk to ignore SNYK-JS-LODASH-450202

We'll address this as soon as the fix which hit the master branch of lodash a few days ago is released. See this PR: lodash/lodash#4336

I did not find any examples of defaultsDeep in our code base.

Signed-off-by: Spencer Norman <spencern@gmail.com>
Signed-off-by: Spencer Norman <spencern@gmail.com>
@spencern spencern requested a review from willopez July 5, 2019 20:53
Copy link
Member

@willopez willopez left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Small change

.snyk Outdated
No remediation available at this time. I cannot find any examples of
defaultsDeep in our codebase. Tracking this PR for release:
https://github.com/lodash/lodash/pull/4336
expires: '2019-07-11T20:17:33.015Z'
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Needs new line at end of file.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks.

Signed-off-by: Spencer Norman <spencern@gmail.com>
@spencern spencern changed the title Spencer chore snyk ignore lodash chore: snyk ignore lodash Jul 5, 2019
Copy link
Member

@willopez willopez left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@spencern spencern merged commit 9a41f8d into master Jul 5, 2019
@spencern spencern deleted the spencer-chore-snyk-ignore-lodash branch July 5, 2019 21:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants