Skip to content

Conversation

@9kopb
Copy link

@9kopb 9kopb commented Nov 28, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
No Proof of Concept
critical severity 679/1000
Why? Has a fix available, CVSS 9.3
Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962463
No No Known Exploit
medium severity 641/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.4
Prototype Pollution
SNYK-JS-JSON5-3182856
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: ethereumjs-util The new version differs by 40 commits.
  • 3e72947 Release commit for v5.1.3
  • 279ac78 Updated deprecated babel es2015 to env preset
  • 3d05254 chore(package): update babelify to version 8.0.0
  • aed81b9 Merge pull request #106 from ethereumjs/greenkeeper/karma-2.0.0
  • acc9130 chore(package): update karma to version 2.0.0
  • a65787d Merge pull request #102 from ethereumjs/greenkeeper/karma-detect-browsers-2.2.6
  • deb4019 chore(package): update karma-detect-browsers to version 2.2.6
  • 193a119 Merge pull request #98 from ethereumjs/greenkeeper/mocha-4.0.0
  • f0aafb0 Update travis to build with Node 8 (from Node 7)
  • 5d59ad6 Merge branch 'master' into greenkeeper/mocha-4.0.0
  • 9e6cda9 Merge pull request #96 from ethereumjs/greenkeeper/coveralls-3.0.0
  • 7f31795 Merge branch 'master' into greenkeeper/coveralls-3.0.0
  • 15d4085 Merge pull request #91 from ethereumjs/greenkeeper/documentation-5.2.0
  • 0c0f23f Rebuild docs with new documentation version
  • d75a4b2 Updated build:docs command to reflect syntax changes from updated documentation version
  • 0bc0616 Merge branch 'master' into greenkeeper/documentation-5.2.0
  • d282700 Merge pull request #105 from egodigitus/master
  • c46a584 Typo fixed
  • c4ab674 Merge pull request #104 from ethereumjs/add-changelog
  • f8037e6 Added CHANGELOG
  • 926f2d7 Merge pull request #100 from subramanianv/zeroAddress
  • aecb58a Zero Address Function
  • 3514e77 Added is zero function
  • 83c909b Added isZeroAddress

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Prototype Pollution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants