`lodash` has a prototype pollution vulnerability, there is a nearly-trivial PR open which will fix it, and the maintainer is just... ignoring it?https://github.com/lodash/lodash/pull/4745#issuecomment-622477124 …
-
Show this thread
-
In fact, there's a second PR open which will also fix the issue, and which is also being ignored! https://github.com/lodash/lodash/pull/4759 … Both PRs are around two months old at this stage
2 replies 0 retweets 6 likesShow this thread
I respect the right of a programmer to not be compelled to do free work for other people, which is why one of the possible resolutions we've discussed at work is to just find the guy and bribe him to push the button
8:21 AM - 29 Jun 2020
0 replies
3 retweets
18 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.