Skip to content

[Snyk] Upgrade web3 from 1.7.1 to 1.10.2#219

Open
ReeceKidd wants to merge 1 commit intomainfrom
snyk-upgrade-b2834ffb601de7df38e785cba71896d2
Open

[Snyk] Upgrade web3 from 1.7.1 to 1.10.2#219
ReeceKidd wants to merge 1 commit intomainfrom
snyk-upgrade-b2834ffb601de7df38e785cba71896d2

Conversation

@ReeceKidd
Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade web3 from 1.7.1 to 1.10.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 24 versions ahead of your current version.
  • The recommended version was released 21 days ago, on 2023-08-28.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Information Exposure
SNYK-JS-SIMPLEGET-2361683
547/1000
Why? Proof of Concept exploit, CVSS 8.8
Proof of Concept
Denial of Service (DoS)
SNYK-JS-DECODEURICOMPONENT-3149970
547/1000
Why? Proof of Concept exploit, CVSS 8.8
Proof of Concept
Prototype Poisoning
SNYK-JS-QS-3153490
547/1000
Why? Proof of Concept exploit, CVSS 8.8
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-COOKIEJAR-3149984
547/1000
Why? Proof of Concept exploit, CVSS 8.8
Proof of Concept
Open Redirect
SNYK-JS-GOT-2932019
547/1000
Why? Proof of Concept exploit, CVSS 8.8
No Known Exploit
Open Redirect
SNYK-JS-GOT-2932019
547/1000
Why? Proof of Concept exploit, CVSS 8.8
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTTPCACHESEMANTICS-3248783
547/1000
Why? Proof of Concept exploit, CVSS 8.8
Proof of Concept
Prototype Pollution
SNYK-JS-MINIMIST-2429795
547/1000
Why? Proof of Concept exploit, CVSS 8.8
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: web3
  • 1.10.2 - 2023-08-28

    Fixed

    • Fixed broken fetch for Node.js > 18.x and fixed double callback (#6381)
  • 1.10.1 - 2023-08-14

    Fixed

    • Builds fixed by updating all typescript versions to 4.9.5 (#6238)
    • ABI encoding for large negative ints (#6239)
    • Updated type file for submitWork parameters, accepts 3 parameters instead of an array (#5200)

    Changed

    • Replace ethereumjs-util with @ ethereumjs/util (#6283)
  • 1.10.1-rc.0 - 2023-08-08

    Fixed

    • Builds fixed by updating all typescript versions to 4.9.5 (#6238)
    • ABI encoding for large negative ints (#6239)
    • Updated type file for submitWork parameters, accepts 3 parameters instead of an array (#5200)

    Changed

    • Replace ethereumjs-util with @ ethereumjs/util (#6283)
  • 1.10.0 - 2023-05-10
  • 1.10.0-rc.0 - 2023-05-02
  • 1.9.0 - 2023-03-20
  • 1.9.0-rc.0 - 2023-03-07
  • 1.8.2 - 2023-01-30
  • 1.8.2-rc.0 - 2023-01-11
  • 1.8.1 - 2022-11-10
  • 1.8.1-rc.0 - 2022-10-28
  • 1.8.0 - 2022-09-14
  • 1.8.0-rc.0 - 2022-09-08
  • 1.7.5 - 2022-08-01
  • 1.7.5-rc.1 - 2022-07-19
  • 1.7.5-rc.0 - 2022-07-15
  • 1.7.4 - 2022-06-21
  • 1.7.4-rc.2 - 2022-06-16
  • 1.7.4-rc.1 - 2022-06-08
  • 1.7.4-rc.0 - 2022-05-17
  • 1.7.3 - 2022-04-08
  • 1.7.3-rc.0 - 2022-04-07
  • 1.7.2 - 2022-04-07
  • 1.7.2-rc.0 - 2022-03-24
  • 1.7.1 - 2022-03-03
from web3 GitHub release notes
Commit messages
Package name: web3
  • 813860d build for 1.10.2
  • 6b1a804 v1.10.2
  • e5c18a2 npm audit fix and build
  • 5fea714 change log update
  • 9e063ef Fixed broken fetch for Node.js > 18.x and fixed double callback (#6381)
  • 3e685bf Release/1.10.1 (#6329)
  • 1b65ccf codeowners update (#6324)
  • d4217a2 1x doc updates (#6325)
  • 5f02175 Replace ethereumjs-util with @ ethereumjs/util (#6283)
  • e68194b 1.x - update submit work and contract.myMethod.send docs (#6229)
  • 47b9769 Fix for ABI encoding large negative ints (#6239)
  • 512aba7 Bump `typescript` to `4.9.5` and `ts-node` to `10.9.1` (#6238)
  • 6bde558 Release/1.10.0 (#6058)
  • 13a2edc Remove the unnecessary chainId parameter (#5888) (#6057)
  • 7b3ce91 1x update (#6044)
  • 195cd3c Filter option doesn't work in getPastEvents (#6015)
  • 48958ee Nicos99/revert call (#6009)
  • 6ce085b Fix error: "n.data.substring is not a function" (#6000)
  • 4e5afa1 Format `transaction.type` to hex. Add empty `accessList` is `tx.type === '0x1'` (#5979)
  • 9238e10 Bump webpack from 5.75.0 to 5.76.0 (#5925)
  • 2097f8d Improve logging of connection errors (#5955)
  • b4d1272 Create CODEOWNERS (#5952)
  • 11bb4d4 github conf for stale issues and PRs (#5893)
  • 46d414b Release/1.9.0 (#5895)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants