Skip to content

Inquiry about lodash dependency updates #1023

@JappiPatel

Description

@JappiPatel

Summary

We're downstream users of jsonwebtoken (via cf-nodejs-logging-support) and noticed PR #1022 addressing lodash vulnerabilities. Would appreciate any information about the status of this PR.

Impact

Our security scans flag jsonwebtoken@9.0.3 due to vulnerable lodash sub-packages including lodash.includes, lodash.isnumber, lodash.isboolean, etc.

CVEs:

Question

If possible, could you share:

  1. Any updates on PR fix(deps): remove lodash dependencies #1022?
  2. Approximate timeline for a release?
  3. Whether there's anything blocking progress that we might help with?

We're available to help with testing if useful.

Context

  • Dependency chain: Our app → cf-nodejs-logging-support@7.4.5 → jsonwebtoken@9.0.3

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions