OriginProtocol / origin-playground

Playground for us to try out new ideas, specifically around Identity (ERC 725) & the Origin Marketplace
https://playground.originprotocol.com
MIT License
159 stars 72 forks source link

[Snyk] Fix for 1 vulnerabilities #24

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-NODEFORGE-598677
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: ipfs The new version differs by 163 commits.
  • 0ddfb8e chore: release version v0.34.0
  • ba3ff42 chore: update contributors
  • c802224 docs: update custom-ipfs-repo example (#1825)
  • 1c70de2 chore: update to Web UI v2.3.3 (#1822)
  • 4214ac0 chore: release version v0.34.0-rc.1
  • 9dce448 chore: update contributors
  • 6de6adf refactor: switch to bignumber.js (#1803)
  • 8ca6471 feat: update to Web UI v2.3.2 (#1807)
  • f7ece99 chore: update webui to v2.3.1 (#1802)
  • 7bcc496 feat: update Web UI to v2.3.0 (#1786)
  • 740b51c chore: rename peer-star-app peer-base
  • 48d3e2b fix: sharness tests (#1787)
  • 70a8cfe chore: release version v0.34.0-rc.0
  • 3c4ef82 chore: update contributors
  • 7315aa1 feat: add `addFromFs` method (#1777)
  • 236c521 docs: add link to nyc list generator
  • 6d46e2e feat: cid base option (#1552)
  • 3659d7e fix: link to Github profile for David Dias
  • dc4be3f chore: lint cleanup (#1779)
  • 8cd4d54 chore: increase silent test timeout and also clean up node (#1775)
  • 5e555ef test: tests and fixes for CID version agnostic read and write (#1757)
  • d5ac655 chore: update dependencies (#1758)
  • b6a7ab6 feat: add from url/stream (#1773)
  • c5e5c07 refactor: modularise files (#1772)
See the full diff
Package name: ipfs-api The new version differs by 27 commits.
  • f382ac0 chore: release version v26.0.3
  • 2856afe chore: update contributors
  • 7fb2cff chore: release version v26.0.2
  • 75e0771 chore: update contributors
  • ddf8bee chore: release version v26.0.1
  • a8f37d6 chore: update contributors
  • 0b46750 fix: pin.ls ignored opts when hash was present (#875)
  • 9eaaea3 chore: release version v26.0.0
  • 3f927a9 chore: update contributors
  • 979d8b5 fix: add missing and remove unused dependencies (#879)
  • 0652ac0 chore: update to ipld-dag-cbor 0.13
  • c534375 chore: remove ipld formats re-export (#872)
  • ef49e95 feat: ipns over pubsub (#846)
  • 14a4471 chore: release version v25.0.0
  • 07d6351 chore: update contributors
  • 834934f fix: add bl module to package dependencies (#853) (#854)
  • 68503cc chore: require just functions needed from lodash (#865)
  • c510cb7 fix: add lodash dependency (#873)
  • 180da77 fix: >150mb bodies no longer crashing Chromium (#868)
  • afc5724 chore: set minimal node version to 8 (#847)
  • 118a965 small fix to bundle-browserify for recent js-ipfs-api (#849)
  • cffbca7 chore: release version v24.0.2
  • e0e2db0 chore: update contributors
  • e290a38 fix: block.put options (#844)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic