-
Notifications
You must be signed in to change notification settings - Fork 6
Open
Description
As is described in this post:
https://medium.com/gulpjs/gulp-util-ca3b1f9f9ac5
It would be nice to update this package to avoid the deprecated gulp-util dependency.
An analysis from npm audit throws this information:
# npm audit report
lodash.template *
Severity: high
Command Injection in lodash - https://github.com/advisories/GHSA-35jh-r3h4-6jhm
No fix available
node_modules/lodash.template
gulp-util >=1.1.0
Depends on vulnerable versions of lodash.template
node_modules/gulp-util
gulp-html-partial *
Depends on vulnerable versions of gulp-util
node_modules/gulp-html-partial
3 high severity vulnerabilities
Some issues need review, and may require choosing
a different dependency.
Metadata
Metadata
Assignees
Labels
No labels