Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade ethers from 5.0.31 to 5.3.0 #57

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

@snyk-bot snyk-bot commented Jun 1, 2021

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • remix-lib/package.json
    • remix-lib/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: ethers The new version differs by 90 commits.
  • 4e6d121 Updated dist files.
  • bfcd05f Added MinInt256 and MaxInt256 constants (#1576).
  • 819b1ac Version bumps for bn.js and hash.js to match elliptic and fix some build tools (Refactor remix lib ethereum/remix#1478).
  • 4b33114 Removed Hangul checks in shims which crashes Android (#1519).
  • 7adcf3b Fixed ENS namehash with leading and trailing dots (#1605).
  • 630656e Fixed broken variable in template string (#1624, #1626).
  • 8681cd5 Fixed FixedNumber rounding for non-default formats (#1629).
  • 470551e Update ws dependency version to fix security (#1633, #1634).
  • d395d16 admin: flags for karma to prevent timeout
  • 8077ce0 Updated dist files.
  • 2fe78ad ci: Removing Pocket network from the default provider and tests as it is not currently reliable
  • 5f1f2c5 Updated dist files
  • 3c79ee8 admin: added words to spellcheck
  • 772067a admin: added words to spellchecker
  • 621897f More resiliant testing.
  • d3b7130 Merge branch 'master' of github.com:ethers-io/ethers.js
  • dad3829 Updated dist files.
  • de4d683 admin: moved some changelog links around
  • ebe4cc9 admin: updated Changelog
  • 35e3bf9 admin: dependency security audit updates
  • 2d717dc docs: updated banner version.
  • 3316468 More aggresively check for mempool transactions sent from JsonRpcSigner.
  • 5144acf Added initial support for detecting replacement transactions (#1477).
  • aadc5cd Added convenience method for HD path derivation.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

…ulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-WS-1296835
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
1 participant