Skip to content
This repository has been archived by the owner on Sep 13, 2024. It is now read-only.

Update dependency elliptic to 6.5.4 [SECURITY] #222

Merged
merged 1 commit into from
Jan 26, 2022

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Dec 8, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change
elliptic 6.5.3 -> 6.5.4

GitHub Vulnerability Alerts

CVE-2020-28498

The npm package elliptic before version 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.


Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, click this checkbox.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot added the renovate label Dec 8, 2021
@renovate renovate bot force-pushed the renovate/npm-elliptic-vulnerability branch 2 times, most recently from 35058c9 to 0244b94 Compare December 25, 2021 03:11
@renovate renovate bot force-pushed the renovate/npm-elliptic-vulnerability branch 2 times, most recently from 2f5bc96 to 15ec563 Compare January 3, 2022 02:32
@renovate renovate bot force-pushed the renovate/npm-elliptic-vulnerability branch from 15ec563 to 1a674a2 Compare January 15, 2022 03:23
@renovate renovate bot force-pushed the renovate/npm-elliptic-vulnerability branch 3 times, most recently from 21eb276 to fefe924 Compare January 26, 2022 13:37
@renovate renovate bot force-pushed the renovate/npm-elliptic-vulnerability branch from fefe924 to 766717a Compare January 26, 2022 13:56
@hrigner hrigner merged commit f7ef587 into master Jan 26, 2022
@hrigner hrigner deleted the renovate/npm-elliptic-vulnerability branch January 26, 2022 14:18
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants