Skip to content

Comments

ZK-76: upgrade elliptic to fix a vulnerability#262

Open
minhbsq wants to merge 1 commit intomainfrom
zk74-upgrade-elliptic
Open

ZK-76: upgrade elliptic to fix a vulnerability#262
minhbsq wants to merge 1 commit intomainfrom
zk74-upgrade-elliptic

Conversation

@minhbsq
Copy link
Contributor

@minhbsq minhbsq commented Feb 25, 2025

This PR upgrade elliptic package (an indirect dependency) to v6.6.1
Detail: GHSA-vjh7-7g9h-fjfh

Test

Recompiling the contract passed

@minhbsq minhbsq changed the title ZK-74: upgrade elliptic to fix a vulnerability ZK-76: upgrade elliptic to fix a vulnerability Feb 25, 2025
@minhbsq minhbsq requested a review from haoze-grvt February 25, 2025 23:42
Copy link

@eimantas-grvt eimantas-grvt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, only comment about version ranges used in the package-lock.json file, could be that after changing from a caret range to an exact version the lock file did not reflect the change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants