Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix denial of service security violation #473

Closed
wouterbeek opened this issue Aug 29, 2021 · 1 comment
Closed

Fix denial of service security violation #473

wouterbeek opened this issue Aug 29, 2021 · 1 comment

Comments

@wouterbeek
Copy link

wouterbeek commented Aug 29, 2021

Projects that use the latest version of ink as a dependency are currently flagged for this security violation. The violation is already fixed downstream in dependency ws, but requires ink to upgrade from ^7.2.5 to ^7.4.6.

PS: yarn audit is know to be unreliable in reporting security issues, see for example this article, but upstream users do have to investigate each violation. So upgrading dependency ws will save a lot of people a lot of time.

@vadimdemedes
Copy link
Owner

Fixed in 3.2.0, thanks for reporting!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants