Replies: 1 comment
-
Considering 9 millions+ weekly downloads, this seems like a valid request. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello jest-dom maintainers,
I hope this message finds you well. I'm reaching out to discuss a dependency version issue in jest-dom that is impacting the security and compliance of projects that depend on your library.
As of the current latest release (v6.4.2), jest-dom still references lodash v4.17.15. Our project is required to use lodash v4.17.17 or higher due to important security patches introduced in later versions.
Could you please consider updating the lodash dependency to v4.17.17 or higher in the next release of jest-dom? This change would help ensure compliance with security requirements and benefit the community by keeping the library up-to-date with secure dependencies.
Thank you for considering this request and for your continuous efforts in maintaining this valuable library. I am looking forward to your response and am happy to assist in testing or other ways if needed.
Beta Was this translation helpful? Give feedback.
All reactions