Open bmorphism opened 2 years ago
thanks! I just upgraded and pushed a version with latest packages for most items.
Currently still have prototype pollution in protobufjs via @cosmjs/proto-signing βΒ this seems to be taken care of https://github.com/cosmos/cosmjs/blob/main/packages/proto-signing/package.json#L78 since the version matches up. I'll dig more into why even after upgrading it still shows in audit.
$ yarn audit report
yarn audit v1.22.17
βββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β high β Prototype Pollution in protobufjs β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Package β protobufjs β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Patched in β >=6.11.3 β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Dependency of β @osmonauts/telescope β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Path β @osmonauts/telescope > cosmwasm-typescript-gen > β
β β @cosmjs/proto-signing > protobufjs β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β More info β https://www.npmjs.com/advisories/1070483 β
βββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
βββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β high β Prototype Pollution in protobufjs β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Package β protobufjs β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Patched in β >=6.11.3 β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Dependency of β @osmonauts/telescope β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Path β @osmonauts/telescope > cosmwasm-typescript-gen > β
β β @cosmjs/stargate > @cosmjs/proto-signing > protobufjs β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β More info β https://www.npmjs.com/advisories/1070483 β
βββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
2 vulnerabilities found - Packages audited: 787
Severity: 2 High
I'm working on some telescope upgrades if that's the issue, will be taken care of ASAP.
omg! I opened my Inbox and this is already for the most part fixed, at least for the issues that required intervention!
You, Ser, are seriously gmi! appreciate the quick turn-around -- want to use it with a Svelte dApp!