Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: Upgrade elliptic to address security vulnerability #30037

Merged
merged 5 commits into from
Aug 14, 2024

Conversation

jennifer-shehane
Copy link
Member

@jennifer-shehane jennifer-shehane commented Aug 14, 2024

Additional details

This addresses a critical vulnerability that was surfaced here: https://security.snyk.io/vuln/SNYK-JS-ELLIPTIC-7577916

This was in our @cypress/webpack-batteries-included-preprocessor package as a sub dependency of another dependency. Issue opened for that package here: browserify/crypto-browserify#234

Steps to test

How has the user experience changed?

PR Tasks

@jennifer-shehane jennifer-shehane self-assigned this Aug 14, 2024
@@ -44,7 +44,7 @@ module.exports = (on) => {
}
```

Other than the `typescript` option, this preprocessor supports the same options as [@cypress/webpack-preprocessor](https://github.com/cypress-io/cypress/tree/develop/npm/webpack-preprocessor#readme), so see its README for more information.
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just a file change to trigger the release in this package which is triggered by any file update in this package directory. This change is unrelated.

@jennifer-shehane
Copy link
Member Author

Snyk check is passing now.

Copy link

cypress bot commented Aug 14, 2024

cypress    Run #56536

Run Properties:  status check passed Passed #56536  •  git commit dcc5678ab4: fix: inconsequential update to trigger a release
Project cypress
Branch Review fix-elliptic-vulnerability
Run status status check passed Passed #56536
Run duration 24m 17s
Commit git commit dcc5678ab4: fix: inconsequential update to trigger a release
Committer Jennifer Shehane
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 8
Tests that did not run due to a developer annotating a test with .skip  Pending 1328
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 29312
View all changes introduced in this branch ↗︎
UI Coverage  43.4%
  Untested elements 218  
  Tested elements 171  
Accessibility  91.26%
  Failed rules  5 critical   10 serious   2 moderate   2 minor
  Failed elements 945  

@jennifer-shehane jennifer-shehane merged commit 07bc653 into develop Aug 14, 2024
84 of 85 checks passed
@jennifer-shehane jennifer-shehane deleted the fix-elliptic-vulnerability branch August 14, 2024 15:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants