The latest version of npm has a new audit feature to expose potential vulnerabilities. There is currently a low severity vulnerability in lodash.
The issue is patched in lodash v4.17.5+
Async is currently on lodash v4.14.0 (https://github.com/caolan/async/blob/master/package.json#L22)
More details on https://nodesecurity.io/advisories/577
I see there are also plans to drop lodash. That would fix this as well.
The latest version of npm has a new audit feature to expose potential vulnerabilities. There is currently a low severity vulnerability in lodash.
The issue is patched in lodash v4.17.5+
Async is currently on lodash v4.14.0 (https://github.com/caolan/async/blob/master/package.json#L22)
More details on https://nodesecurity.io/advisories/577
I see there are also plans to drop lodash. That would fix this as well.