Skip to content

Security Vulnerability: lodash.isDate Dependency in @salesforce/design-system-react #3182

@hkmadhusudhan

Description

@hkmadhusudhan

Hi team,

We've identified a security vulnerability associated with the lodash.isDate package, which is still being used as a dependency in the latest version of @salesforce/design-system-react.

https://www.npmjs.com/package/lodash.isdate

The lodash.isDate package has not received any updates in over 9 years.
A security issue has been flagged in this library, raising concerns about its continued usage.
The latest release of @salesforce/design-system-react still includes this dependency.

Could you please confirm:

Whether any APIs or functions from lodash.isDate are actively used within the package?
If there are any plans to remove or replace this dependency with a more secure and actively maintained alternative?

Thanks for looking into this! Looking forward to hearing back from you.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions