OpenZeppelin / defender-client

Monorepo for all defender-client npm packages
https://docs.openzeppelin.com/defender/
MIT License
56 stars 47 forks source link

[Snyk] Security upgrade web3 from 1.10.4 to 4.0.1 #623

Open tirumerla opened 1 week ago

tirumerla commented 1 week ago

snyk-top-banner

Snyk has created this PR to fix 4 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory. If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning ``` Failed to update the yarn.lock, please update manually before merging. ```

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Asymmetric Resource Consumption (Amplification)
SNYK-JS-BODYPARSER-7926860
  696  
medium severity Cross-site Scripting
SNYK-JS-EXPRESS-7926867
  541  
low severity Cross-site Scripting
SNYK-JS-SEND-7926862
  391  
low severity Cross-site Scripting
SNYK-JS-SERVESTATIC-7926865
  391  

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report 📜 Customise PR templates 🛠 Adjust project settings 📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting

socket-security[bot] commented 1 week ago

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@aws-crypto/util@1.2.2 None 0 26.7 kB aws-crypto-tools-ci-bot
npm/@aws-sdk/types@3.465.0 None +1 125 kB aws-sdk-bot
npm/@aws-sdk/util-utf8-browser@3.259.0 None 0 20 kB aws-sdk-bot
npm/@babel/code-frame@7.24.2 environment 0 24.1 kB nicolo-ribaudo
npm/@babel/helper-validator-identifier@7.24.5 None 0 49.2 kB nicolo-ribaudo
npm/@babel/highlight@7.24.5 environment 0 20.3 kB nicolo-ribaudo
npm/@eslint-community/eslint-utils@4.4.0 None 0 379 kB eslint-community-bot
npm/@eslint-community/regexpp@4.10.0 None 0 431 kB eslint-community-bot
npm/@jest/expect-utils@29.7.0 None 0 28.3 kB simenb
npm/@jest/schemas@29.6.3 None 0 6.07 kB simenb
npm/@jest/types@29.6.3 None 0 32.7 kB simenb
npm/@npmcli/fs@3.1.0 filesystem 0 26.5 kB lukekarrys
npm/@openzeppelin/defender-base-client@1.54.0-rc.0 None 0 2.46 kB collins-oz
npm/@openzeppelin/defender-relay-client@1.54.0-rc.0 None 0 19.2 kB collins-oz
npm/@sinclair/typebox@0.27.8 None 0 442 kB sinclair
npm/@smithy/types@2.7.0 None 0 234 kB smithy-team
npm/@types/glob@8.1.0 None 0 6.66 kB types
npm/@types/istanbul-lib-coverage@2.0.6 None 0 5.45 kB types
npm/@types/istanbul-lib-report@3.0.3 None 0 7.92 kB types
npm/@types/istanbul-reports@3.0.4 None 0 6.68 kB types
npm/@types/jest@29.5.12 None 0 78.7 kB types
npm/@types/json-schema@7.0.15 None 0 31.7 kB types
npm/@types/lodash@4.17.4 None 0 863 kB types
npm/@types/minimatch@5.1.2 None 0 12.5 kB types
npm/@types/node@16.18.97 None 0 1.8 MB types
npm/@types/semver@7.5.8 None 0 23.3 kB types
npm/@types/stack-utils@2.0.3 None 0 6.43 kB types
npm/@types/yargs-parser@21.0.3 None 0 8.65 kB types
npm/@types/yargs@17.0.32 None 0 60.2 kB types
npm/@typescript-eslint/eslint-plugin@5.62.0 None 0 2.43 MB jameshenry
npm/@typescript-eslint/scope-manager@5.62.0 None 0 592 kB jameshenry
npm/@typescript-eslint/type-utils@5.62.0 None 0 88 kB jameshenry
npm/@typescript-eslint/types@5.62.0 None 0 223 kB jameshenry
npm/@typescript-eslint/typescript-estree@5.62.0 environment, filesystem 0 553 kB jameshenry
npm/@typescript-eslint/utils@5.62.0 None 0 501 kB jameshenry
npm/@typescript-eslint/visitor-keys@5.62.0 None 0 18.4 kB jameshenry
npm/amazon-cognito-identity-js@6.3.7 network 0 1.39 MB aws-amplify-ops
npm/ansi-regex@5.0.1 None 0 5.61 kB qix
npm/async-retry@1.3.3 None 0 5.21 kB leerobinson
npm/axios@1.6.2 network 0 1.8 MB jasonsaayman
npm/balanced-match@1.0.2 None 0 6.94 kB juliangruber
npm/base64-js@1.5.1 None 0 9.62 kB feross
npm/braces@3.0.3 None 0 44.6 kB jonschlinkert
npm/buffer@4.9.2 None 0 264 kB feross
npm/ci-info@3.9.0 environment 0 26.1 kB sibiraj-s
npm/color-name@1.1.4 None 0 6.69 kB dfcreative
npm/concat-map@0.0.1 None 0 4.86 kB substack
npm/debug@4.3.4 environment 0 42.4 kB qix
npm/delayed-stream@1.0.0 None 0 8.02 kB apechimp
npm/eslint-scope@5.1.1 None 0 78.4 kB eslintbot
npm/eslint-visitor-keys@3.4.3 None 0 32.3 kB eslintbot
npm/esrecurse@4.3.0 None 0 13.5 kB michaelficarra
npm/estraverse@5.3.0 None 0 37.1 kB michaelficarra
npm/expect@29.7.0 None 0 146 kB simenb
npm/fill-range@7.1.1 None 0 16.7 kB jonschlinkert
npm/follow-redirects@1.15.1 network 0 27.7 kB rubenverborgh
npm/globby@11.1.0 filesystem 0 21.8 kB sindresorhus
npm/graphemer@1.4.0 None 0 812 kB mattpauldavies
npm/ieee754@1.2.1 None 0 6.8 kB feross
npm/is-glob@4.0.3 None 0 13.6 kB phated
npm/is-number@7.0.0 None 0 9.62 kB jonschlinkert
npm/isomorphic-unfetch@3.1.0 None 0 2.5 kB developit
npm/jest-matcher-utils@29.7.0 None 0 28.4 kB simenb
npm/jest-message-util@29.7.0 None 0 20.6 kB simenb
npm/jest-util@29.7.0 environment 0 41.8 kB simenb
npm/js-tokens@4.0.0 None 0 15.1 kB lydell
npm/lodash@4.17.21 None 0 1.41 MB bnjmnt4n
npm/micromatch@4.0.7 None 0 56.3 kB paulmillr
npm/mime-db@1.52.0 None 0 206 kB dougwilson
npm/mimic-fn@2.1.0 None 0 4.46 kB sindresorhus
npm/ms@2.1.2 None 0 6.84 kB styfle
npm/natural-compare-lite@1.4.0 None 0 5.63 kB lauriro
npm/picocolors@1.0.1 environment 0 5.15 kB alexeyraspopov
npm/picomatch@2.3.1 None 0 90 kB mrmlnc
npm/react-is@18.3.1 environment 0 24 kB react-bot
npm/slash@3.0.0 None 0 3.51 kB sindresorhus
npm/sprintf-js@1.0.3 None 0 34.8 kB alexei
npm/stack-utils@2.0.6 unsafe 0 14.6 kB isaacs
npm/string_decoder@1.3.0 None 0 14.4 kB matteo.collina
npm/to-regex-range@5.0.1 None 0 22.9 kB jonschlinkert
npm/tr46@0.0.3 None 0 268 kB sebmaster
npm/tsutils@3.21.0 None 0 382 kB ajaff
npm/undici-types@5.26.5 None 0 73.1 kB ethan_arrowood
npm/util-deprecate@1.0.2 None 0 5.48 kB tootallnate
npm/whatwg-url@5.0.0 None 0 49.9 kB domenic
npm/wrappy@1.0.2 None 0 2.96 kB zkat
npm/yallist@4.0.0 None 0 14.8 kB isaacs

View full report↗︎