Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

8 NPM Audit Vulnerabilities #38

Open
SilentRhetoric opened this issue Oct 31, 2024 · 1 comment · May be fixed by #39
Open

8 NPM Audit Vulnerabilities #38

SilentRhetoric opened this issue Oct 31, 2024 · 1 comment · May be fixed by #39

Comments

@SilentRhetoric
Copy link

SilentRhetoric commented Oct 31, 2024

While initializing a project with a front end, NPM audit reports 8 high severity vulnerabilities. Upgrading to Use Wallet v3 may address this (see #35).


ws  7.0.0 - 7.5.9
Severity: high
ws affected by a DoS when handling a request with many HTTP headers - https://github.com/advisories/GHSA-3h5v-q93c-6h6q
No fix available
node_modules/ws
  @walletconnect/socket-transport  *
  Depends on vulnerable versions of ws
  node_modules/@walletconnect/socket-transport
    @walletconnect/core  <=1.8.0
    Depends on vulnerable versions of @walletconnect/socket-transport
    node_modules/@walletconnect/core
      @walletconnect/client  <=1.8.0
      Depends on vulnerable versions of @walletconnect/core
      node_modules/@walletconnect/client
        @blockshake/defly-connect  *
        Depends on vulnerable versions of @walletconnect/client
        node_modules/@blockshake/defly-connect
        @daffiwallet/connect  *
        Depends on vulnerable versions of @walletconnect/client
        node_modules/@daffiwallet/connect
          @txnlab/use-wallet  *
          Depends on vulnerable versions of @blockshake/defly-connect
          Depends on vulnerable versions of @daffiwallet/connect
          Depends on vulnerable versions of @perawallet/connect
          node_modules/@txnlab/use-wallet
        @perawallet/connect  *
        Depends on vulnerable versions of @walletconnect/client
        node_modules/@perawallet/connect

8 high severity vulnerabilities

Some issues need review, and may require choosing
a different dependency.```
@neilcampbell
Copy link
Contributor

Thanks for flagging

@neilcampbell neilcampbell linked a pull request Nov 8, 2024 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants