bitpay / bitcore

A full stack for bitcoin and blockchain-based applications
https://bitcore.io/
MIT License
4.85k stars 2.09k forks source link

Security issue: insecure cryptography and dependencies #3666

Open paulmillr opened 9 months ago

paulmillr commented 9 months ago

https://github.com/bitpay/bitcore/blob/f778e62c3bcaa6799f8be0bd870d7e3910d7e16f/packages/bitcore-lib/package.json#L43

has been long unmaintained; and had a few CVEs. I suggest doing following actions:

kajoseph commented 9 months ago

Thanks for the suggestions and concern. We're actively looking into and addressing this