Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @ethereumjs/common from 2.4.0 to 3.0.0 #56

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from

Conversation

PinkDiamond1
Copy link
Owner

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • src/chains/ethereum/block/package.json
    • src/chains/ethereum/block/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 828/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 8.7
Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-8187303
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

…ck/package-lock.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-ELLIPTIC-8187303
Copy link

New dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@achingbrain/[email protected] network 0 112 kB achingbrain
npm/@assemblyscript/[email protected] None 0 33.1 kB assemblyscript
npm/@discoveryjs/[email protected] None 0 83.4 kB lahmatiy
npm/@filecoin-shipyard/[email protected] None 0 17.9 kB jimpick
npm/@filecoin-shipyard/[email protected] None 0 67.4 kB vascosantos
npm/@filecoin-shipyard/[email protected] None 0 208 kB alanshaw
npm/@hapi/[email protected] None 0 23.4 kB devinivy
npm/@hapi/[email protected] None 0 8.35 kB hueniverse
npm/@hapi/[email protected] None 0 8.38 kB hueniverse
npm/@hapi/[email protected] None 0 28.3 kB devinivy
npm/@hapi/[email protected] None 0 5.55 kB hueniverse
npm/@hapi/[email protected] None 0 5.1 kB hueniverse
npm/@hapi/[email protected] None 0 26.3 kB cjihrig
npm/@hapi/[email protected] None 0 9.42 kB devinivy
npm/@hapi/[email protected] None 0 21.7 kB cjihrig
npm/@hapi/[email protected] None 0 7.31 kB hueniverse
npm/@hapi/[email protected] None 0 6.14 kB hueniverse
npm/@hapi/[email protected] None 0 2.88 kB hueniverse
npm/@hapi/[email protected] network 0 183 kB devinivy
npm/@hapi/[email protected] None 0 6.49 kB cjihrig
npm/@hapi/[email protected] None 0 51.1 kB devinivy
npm/@hapi/[email protected] filesystem 0 24.8 kB cjihrig
npm/@hapi/[email protected] None 0 18.7 kB hueniverse
npm/@hapi/[email protected] None 0 10.1 kB devinivy
npm/@hapi/[email protected] None 0 7.25 kB hueniverse
npm/@hapi/[email protected] None 0 12.9 kB hueniverse
npm/@hapi/[email protected] None 0 24.4 kB devinivy
npm/@hapi/[email protected] network 0 13 kB devinivy
npm/@hapi/[email protected] None 0 16.5 kB devinivy
npm/@hapi/[email protected] None 0 17.5 kB cjihrig
npm/@hapi/[email protected] filesystem 0 14.7 kB hueniverse
npm/@hapi/[email protected] None 0 108 kB hueniverse
npm/@hapi/[email protected] None 0 10.7 kB devinivy
npm/@hapi/[email protected] None 0 213 kB devinivy
npm/@hapi/[email protected] None 0 5.75 kB hueniverse
npm/@hapi/[email protected] network 0 36.7 kB wyatt
npm/@leichtgewicht/[email protected] None 0 21 kB leichtgewicht
npm/@multiformats/[email protected] None 0 9.76 kB mikeal
npm/@protobufjs/[email protected] None 0 9.05 kB dcode
npm/@protobufjs/[email protected] None 0 9.22 kB dcode
npm/@protobufjs/[email protected] None 0 9.14 kB dcode
npm/@protobufjs/[email protected] None 0 7.75 kB dcode
npm/@protobufjs/[email protected] network 0 8.76 kB dcode
npm/@protobufjs/[email protected] None 0 27 kB dcode
npm/@protobufjs/[email protected] None 0 4.29 kB dcode
npm/@protobufjs/[email protected] None 0 7.77 kB dcode
npm/@protobufjs/[email protected] None 0 6.25 kB dcode
npm/@protobufjs/[email protected] None 0 23.5 kB dcode
npm/@sideway/[email protected] None 0 56.3 kB hueniverse
npm/@sideway/[email protected] None 0 16.9 kB hueniverse
npm/@sideway/[email protected] None 0 3.64 kB hueniverse
npm/@sindresorhus/[email protected] None 0 40.2 kB sindresorhus
npm/@sinonjs/[email protected] None 0 38 kB mrgnrdrck
npm/@sinonjs/[email protected] environment, eval 0 156 kB mrgnrdrck
npm/@sinonjs/[email protected] None 0 92.2 kB mrgnrdrck
npm/@sinonjs/[email protected] None 0 650 kB fatso83
npm/@szmarczak/[email protected] None 0 6.3 kB szmarczak
npm/@tokenizer/[email protected] None 0 3.04 kB borewit
npm/@trufflesuite/[email protected] environment, network +1 29.4 MB davidmurdoch
npm/@types/[email protected] None 0 4.51 kB types
npm/@types/[email protected] None 0 7.22 kB types
npm/@types/[email protected] None 0 2.85 kB types
npm/@types/[email protected] None 0 6.77 kB types
npm/@types/[email protected] None 0 164 kB types
npm/@types/[email protected] None 0 22.7 kB types
npm/@types/[email protected] None 0 32.2 kB types
npm/@types/[email protected] None 0 7.97 kB types
npm/@types/[email protected] None 0 3.34 kB types
npm/@types/[email protected] None 0 859 kB types
npm/@types/[email protected] None 0 13.2 kB types
npm/@types/[email protected] None 0 8.2 kB types
npm/@types/[email protected] None 0 2.88 kB types
npm/@types/[email protected] None 0 1.64 MB types
npm/@types/[email protected] None 0 6.97 kB types
npm/@types/[email protected] None 0 6.27 kB types
npm/@types/[email protected] None 0 6.14 kB types
npm/@types/[email protected] None 0 18.9 kB types
npm/@webassemblyjs/[email protected] None 0 201 kB xtuc
npm/@webassemblyjs/[email protected] None 0 6.37 kB xtuc
npm/@webassemblyjs/[email protected] None 0 6.11 kB xtuc
npm/@webassemblyjs/[email protected] None 0 8.7 kB xtuc
npm/@webassemblyjs/[email protected] None 0 10.4 kB xtuc
npm/@webassemblyjs/[email protected] None 0 32.4 kB xtuc
npm/@webassemblyjs/[email protected] None 0 19 kB xtuc
npm/@webassemblyjs/[email protected] None 0 5.19 kB xtuc
npm/@webassemblyjs/[email protected] None 0 46.1 kB xtuc
npm/@webassemblyjs/[email protected] None 0 11.3 kB xtuc
npm/@webassemblyjs/[email protected] None 0 29.4 kB xtuc
npm/@webassemblyjs/[email protected] None 0 23.9 kB xtuc
npm/@webassemblyjs/[email protected] None 0 9.34 kB xtuc
npm/@webassemblyjs/[email protected] None 0 123 kB xtuc
npm/@webassemblyjs/[email protected] None 0 37.4 kB xtuc
npm/@webpack-cli/[email protected] None 0 4.38 kB evilebottnawi
npm/@webpack-cli/[email protected] None 0 5.42 kB evilebottnawi
npm/@webpack-cli/[email protected] None 0 18.8 kB evilebottnawi
npm/@xtuc/[email protected] None 0 8.57 kB xtuc
npm/@xtuc/[email protected] None 0 190 kB xtuc
npm/@zxing/[email protected] None 0 7.01 MB odahcam
npm/[email protected] None 0 76.3 kB mysticatea
npm/[email protected] None 0 17.3 kB alanshaw
npm/[email protected] None 0 2.3 kB jsumners
npm/[email protected] None 0 16.6 kB dougwilson
npm/[email protected] None 0 454 kB marijn
npm/[email protected] None 0 7.19 kB raynos
npm/[email protected] None 0 72.9 kB esp
npm/[email protected] eval 0 929 kB esp
npm/[email protected] None +4 57 kB nexdrew
npm/[email protected] None +1 9.57 kB jacobheun
npm/[email protected] environment, filesystem, shell +1 36.3 kB ntwcklng
npm/[email protected] None 0 2.59 kB sindresorhus
npm/[email protected] None 0 10 kB rase-
npm/[email protected] None 0 49.8 kB indutny
npm/[email protected] None 0 5.64 kB chaijs
npm/[email protected] None 0 13.5 kB olliv
npm/[email protected] None 0 27.4 kB alexindigo
npm/[email protected] None 0 2.63 kB ryanzim
npm/[email protected] None 0 6.57 kB davidmarkclements
npm/[email protected] None 0 13.6 kB ljharb
npm/[email protected] None 0 3.1 kB mokesmokes
npm/[email protected] None 0 7.23 kB emilbayes
npm/[email protected] None 0 62.3 kB mikepb
npm/[email protected] None 0 5.04 kB niklasvh
npm/[email protected] None 0 4.69 kB darrachequesne
npm/[email protected] environment 0 5.73 MB chjj
npm/[email protected] None 0 63.9 kB mikemcl
npm/[email protected] None 0 402 kB mikemcl
npm/[email protected] None 0 2.35 MB vadimg
npm/[email protected] None 0 64.4 kB matteo.collina
npm/[email protected] None 0 149 kB dcposch
npm/[email protected] None 0 3.25 kB achingbrain
npm/[email protected] None 0 30.6 kB amitport
npm/[email protected] None 0 99.7 kB fanatid
npm/[email protected] None 0 1.04 MB dignifiedquire
npm/[email protected] None 0 14 kB sindresorhus
npm/[email protected] None 0 8.35 kB achingbrain
npm/[email protected] None 0 6.45 kB cwmma
npm/[email protected] None 0 6.27 kB cwmma
npm/[email protected] None 0 3.68 kB cwmma
npm/[email protected] None 0 14.5 kB cwmma
npm/[email protected] None 0 18.5 kB soldair
npm/[email protected] None 0 290 kB lpinca
npm/[email protected] None 0 87.8 kB chjj
npm/[email protected] None 0 5.07 kB davidgatti
npm/[email protected] None 0 11 kB dougwilson
npm/[email protected] network +2 31.9 kB lukechilds
npm/[email protected] None 0 89.4 kB hildjj

View full report↗︎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants