Skip to content

fix(deps): bump lockfile past critical sha.js/cipher-base/pbkdf2/secp256k1 advisories - #146

Open
JonLittleIT wants to merge 1 commit into
Railgun-Community:mainfrom
JonLittleIT:security/a06-lockfile-audit-fixes
Open

JonLittleIT wants to merge 1 commit into
Railgun-Community:mainfrom
JonLittleIT:security/a06-lockfile-audit-fixes

Conversation

@JonLittleIT

Copy link
Copy Markdown

Summary

  • Refreshes four yarn.lock entries within their existing semver ranges: sha.js 2.4.11 → 2.4.12, cipher-base 1.0.4 → 1.0.7, pbkdf2 3.1.2 → 3.1.6, secp256k1 4.0.3 → 4.0.5.
  • Clears every critical advisory from yarn audit --groups dependencies (294 → 231 advisories; critical count 61 → 0 for these packages). No package.json changes.
  • sha.js/cipher-base are reached via browserify-aes, which src/utils/encryption/aes.ts uses for wallet DB encryption on the browser/React Native path.

Not addressed

  • Remaining advisories come mostly from @railgun-community/circomlibjs → web3 (elliptic, bn.js, base-x, tar, ...); these need an upstream change.
  • ws 8.17.1 is an exact pin in ethers@6.14.3; ethers@6.17.0 uses ws@8.21.0. Bumping ethers is left for a separate change since the engine only uses HTTP JSON-RPC.

Test plan

  • yarn test: 197 passing, 37 pending
  • yarn audit --groups dependencies: no sha.js, cipher-base, pbkdf2 or secp256k1 advisories remain

🤖 Generated with Claude Code

…256k1 advisories

Refresh yarn.lock entries within their existing semver ranges:
sha.js 2.4.11 -> 2.4.12, cipher-base 1.0.4 -> 1.0.7, pbkdf2 3.1.2 -> 3.1.6,
secp256k1 4.0.3 -> 4.0.5. Clears all critical advisories reported by
`yarn audit --groups dependencies`. No package.json changes.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant