You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@jeroen looks like you've added underscore.js back in, but updated it to 1.13.6: dff09bc. I think the way it's included in the linked PR would make it easier to update in the future, but in any case I'll close this as completed now.
The included version of underscore.js, 1.7.0, is vulnerable to an arbitrary code injection attack CVE-2021-23358.
This is fixed is underscore.js 1.12.1.
I suggest we update to the latest underscore release, 1.13.4. Would you accept a PR for this?
The text was updated successfully, but these errors were encountered: