Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Timing Attack
SNYK-JS-ELLIPTIC-511941
No No Known Exploit
Commit messages
Package name: web3 The new version differs by 250 commits.
  • e68246e v1.2.5
  • 37e978e versions bumped
  • cd1790d minified file, CHANGELOG.md, and versions manually updated if required
  • e919f81 v1.2.5-rc.0
  • f0bc893 version in package.json changed back to 1.2.4
  • b8328bb web3.min.js updated
  • a9aaed1 package.json and related package-lock updated
  • 84543a0 Merge pull request #3273 from BesrourMS/patch-1
  • 7f92ba5 version in web3 package manually bumped to 1.2.5-rc to be sure the new version will be set for the version property in the minified file
  • 513116f Merge pull request #3311 from ethereum/test/conf-http
  • 0bf0bc9 Merge branch '1.x' into test/conf-http
  • 3f839c9 Merge pull request #3304 from ethereum/test/e2e-ganache-core
  • 541e71a Fix verdaccio by upgrading to 4.4.2
  • 2058e41 Add tests for wallet method calls with chain/hardfork opts
  • e892151 Add http confirmations test
  • ec86978 Remove proof log line
  • fa8eedf Add ganache-core E2E test. Disable truffle E2E test
  • 9b4b68a Merge pull request #3297 from ethereum/issue/3272
  • 4ff2499 Merge branch '1.x' into issue/3272
  • 9045fd2 missing semicolons added in index of the web3-eth-contract package and in the e2e.contract.events test
  • b0295ea Merge pull request #3298 from ethereum/fix/get-code-failure
  • 054614e Merge branch '1.x' into issue/3272
  • 509d73a CHANGELOG.md updated
  • 56a474e Merge branch '1.x' into fix/get-code-failure

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants