Skip to content

Upgrade lodash packages to lodash 4.17.5+ to address CVE-2018-3721 #4267

@Stephanemw

Description

@Stephanemw
Contributor

Bug or support request summary

Storybooks is using outdated and vulnerable lodash.xxx modules. We should upgrade lodash.xxx modules from 2016 to their modern tree-shakeable lodash packages from lodash 4.17.5 and above

Steps to reproduce

https://nvd.nist.gov/vuln/detail/CVE-2018-3721

Please specify which version of Storybook and optionally any affected addons that you're running

  • @storybook/.4.0.0-alpha.20 and above

Affected platforms

Not platform-specific

Activity

Stephanemw

Stephanemw commented on Oct 3, 2018

@Stephanemw
ContributorAuthor

As discussed in Discord, I'll be raising a PR for this soon.

added a commit that references this issue on Oct 8, 2018
be3ab29
jethrolarson

jethrolarson commented on Dec 21, 2018

@jethrolarson

This broke my instance of storybook. And it does so due to a patch version of lodash, so I'm not a fan.

Stephanemw

Stephanemw commented on May 20, 2019

@Stephanemw
ContributorAuthor

@jethrolarson can you help me understand where this breakage occurs for you? We can't realistically keep on depending on vulnerable libraries so I'm keen to find a resolution that works for you too.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

      Development

      No branches or pull requests

        Participants

        @jethrolarson@gabrielcsapo@Stephanemw@igor-dv

        Issue actions

          Upgrade lodash packages to lodash 4.17.5+ to address CVE-2018-3721 · Issue #4267 · storybookjs/storybook