Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Potential vulnerabilities with dependencies #196

Open
snowkidind opened this issue Aug 3, 2022 · 1 comment
Open

Potential vulnerabilities with dependencies #196

snowkidind opened this issue Aug 3, 2022 · 1 comment

Comments

@snowkidind
Copy link

Please update this packages' dependencies.

Potential vulnerabilities

dependency using should use
ethers 5.0.18 5.6.9
web3 1.3.0 1.7.5

Errors generated by npm audit:

: Insecure Credential Storage in web3
: Arbitrary Code Execution in underscore
: Use of a Broken or Risky Cryptographic Algorithm
: ReDoS in Sec-Websocket-Protocol header
: Got allows a redirect to a UNIX socket

@svax974
Copy link

svax974 commented Jan 15, 2023

This module should indeed really update those dependencies. It causes many problems when trying to use it along with a newer web3 when it is needed in projects.
Is is planned by the team ?
Regards

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants