Closed vincent-l-j closed 1 year ago
This package is marked for deprecation long time ago in 1.x and current active development is going on in 4.x , 4.x is in RC and will be released soon.
Hey @vincent-l-j, just wanted to let you know that in v4 those packages are removed. Since we moved away from those in v4, we are closing this issue.
Is there an existing issue for this?
There is a related issue that mentions the vulnerability in
got
upon whichswarm-js
also depends.Current Behavior
The
swarm-js
dependency inweb3-bzz
depends onrequest
which is deprecated and has a Server-Side Request Forgery vulnerability according to the GitHub Advisory Database. The package-lock.json file inweb3-bzz
was created with an old version of npm. Runningnpm install
insideweb3-bzz
installs packages with vulnerabilities but also warns that theweb3-bzz
api will be deprecated in the next version:The report generated by
npm audit
is:Expected Behavior
Expected
npm audit
to show no vulnerabilities:Steps to Reproduce
Web3.js Version
v1.9.0
Environment
Anything Else?
I emailed security@chainsafe.io a week ago on 3rd April 2023 according to the security policy but haven't received a reply back.