swarmcity / SwarmCityDapp

Swarm City dApp FrontEnd
MIT License
28 stars 10 forks source link

[Snyk] Security upgrade eth-crypto from 1.2.7 to 1.3.4 #916

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SSRI-1085630
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: eth-crypto The new version differs by 48 commits.
  • c5fa437 1.3.4
  • cbf64f0 BUILD
  • 3438518 ADD different readme for npm
  • 7199535 REMOVE babel-eslint
  • 734a029 FIX typings test
  • 0ac0c08 FIX node version
  • 14cf0e9 UPDATE node
  • c322bd8 Update dependency assert to v2
  • 6a2e018 Update dependency babel-loader to v8.0.6
  • 548552a Update dependency karma-babel-preprocessor to v8
  • e5506cf Update dependency mocha to v6
  • b86ef82 Update dependency karma to v4
  • e9a9f9f Update dependency convert-hrtime to v3
  • 81cd331 Update dependency webpack-cli to v3.3.2
  • 93de80a Update dependency typescript to v3.4.5
  • cf8a6bf Update dependency ganache-cli to v6.4.3
  • c4fa19c Update dependency secp256k1 to v3.7.0
  • 97d26bd Update dependency eslint to v5.16.0
  • 75275ea Update dependency async-test-util to v1.7.3
  • 8efe7ae Update dependency eccrypto to v1.1.1
  • 9d44162 Update dependency assert to v1.5.0
  • e5d5ddd Update dependency @ types/bn.js to v4.11.5
  • 0ecc144 ADD(renovate-bot) enable automerge
  • 66582f9 Merge pull request #26 from pubkey/renovate/configure
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic