Closed red-0ne closed 3 months ago
Upgrade the CosmosSDK version to 0.50.5 or newer and ensure that dependabot reports dependency security issues.
0.50.5
dependabot
CosmosSDK had a security issue in versions prior to 0.50.5 and dependabot in the poktroll repository did not catch it.
poktroll
This is the notification received by shannon-sdk's dependabot [1]:
shannon-sdk
https://github.com/pokt-network/shannon-sdk/security/dependabot/3
Creator: [@red-0ne]
Objective
Upgrade the CosmosSDK version to
0.50.5
or newer and ensure thatdependabot
reports dependency security issues.Origin Document
CosmosSDK had a security issue in versions prior to
0.50.5
anddependabot
in thepoktroll
repository did not catch it.This is the notification received by
shannon-sdk
'sdependabot
[1]:https://github.com/pokt-network/shannon-sdk/security/dependabot/3
Goals
dependabot
in thepoktroll
repository catches future security issues.Deliverables
poktroll
's CosmosSDK (github.com/cosmos/cosmos-sdk) dependency to version0.50.5
or newer.poktroll
repository to cach future dependency vulnerabilities.Creator: [@red-0ne]