#1169 High Prototype Pollution risk caused by lodash.omitby/4.6.0 scanned by BlackDuck for @pact-foundation/pact@^12.1.2
Issue created by
Rufei77
Thank you for reporting a bug! We appreciate it very much. Issues are a big input into the priorities for Pact-JS development
All italic text in this template is safe to remove before submitting
Thanks again!
Software versions
Please provide at least OS and version of pact-js
•
OS: Mac OS
•
Consumer Pact library: @pact-foundation/pact@^12.1.2
•
Provider Pact library: @pact-foundation/pact@^12.1.2
•
Node Version: v 18.xx
Issue Checklist
Please confirm the following:
☑︎ I have upgraded to the latest
☑︎ I have the read the FAQs in the Readme
☑︎ I have triple checked, that there are
no unhandled promises in my code and have
read the section on intermittent test failures
☐ I have set my log level to debug and attached a log file showing the complete request/response cycle
☐ For bonus points and virtual high fives, I have created a reproduceable git repository (see below) to illustrate the problem
Expected behaviour
No vulnerabilities reported :)
Actual behaviour
Blackduck scanner report a HIGH severity alert (
CVE-2019-10744 for a dependency (lodash.omitby/4.6.0) used by pact.
pact-foundation/pact-js