ZeroNetJS / zeronet-js

ZeroNet in JS
MIT License
48 stars 9 forks source link

[Snyk] Security upgrade peer-id from 0.10.7 to 0.14.3 #113

Open mkg20001 opened 3 years ago

mkg20001 commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-NODEFORGE-598677
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: peer-id The new version differs by 92 commits.
  • 5468ee0 chore: release version v0.14.3
  • f895151 chore: update contributors
  • e7d0eaa chore: update deps (#137)
  • 41ab96c docs: correct case for RSA keyType (#136)
  • 4178e53 docs: add documentation for isPeerId(id) (#134) (#135)
  • 10ead07 chore: release version v0.14.2
  • d940099 chore: update contributors
  • b2ee342 feat: has inline public key method (#132)
  • ecc1e5b chore: release version v0.14.1
  • 153bc8e chore: update contributors
  • d40d588 fix: ts constructor types (#130)
  • 224b30c fix: privKey possible undefined (#129)
  • 6d571ae fix: typo in readme (#128)
  • ff4bd96 chore: release version v0.14.0
  • 427b46c chore: update contributors
  • d16ce9c fix: replace node buffers with uint8arrays (#127)
  • cd99cb2 chore: release version v0.13.13
  • c295329 chore: update contributors
  • bb32b12 chore: update deps (#126)
  • 6fd5ca2 chore(deps-dev): bump aegir from 21.10.2 to 22.0.0 (#124)
  • 020b963 chore: release version v0.13.12
  • e3da29a chore: update contributors
  • 8cd9dfb feat(cli): add support for specifying type and size (#122)
  • 3598a43 chore: release version v0.13.11
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic