Skip to content

Commit c7b2a64

Browse files
committed
fix: resolve HIGH severity security vulnerabilities
Add yarn resolutions to fix the following vulnerabilities: - validator (GHSA-vghf-hv5q-vc2g): ReDoS vulnerability in isEmail - Resolved by forcing validator@13.15.23 for tronweb dependency - valibot (GHSA-vqpr-j7v3-hqw9): ReDoS vulnerability in EMOJI_REGEX - Resolved by forcing valibot@1.2.0 for @iota/iota-sdk dependency Ticket: BG-0
1 parent 6d02170 commit c7b2a64

File tree

2 files changed

+11
-9
lines changed

2 files changed

+11
-9
lines changed

package.json

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -108,7 +108,9 @@
108108
"request": "npm:@cypress/request@3.0.9",
109109
"**/avalanche/store2": "2.14.4",
110110
"webpack-dev-server": "5.2.1",
111-
"memfs": "4.46.0"
111+
"memfs": "4.46.0",
112+
"**/tronweb/**/validator": "13.15.23",
113+
"**/valibot": "1.2.0"
112114
},
113115
"workspaces": [
114116
"modules/*"

yarn.lock

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -20634,10 +20634,10 @@ v8-compile-cache@^2.0.3:
2063420634
resolved "https://registry.npmjs.org/v8-compile-cache/-/v8-compile-cache-2.4.0.tgz"
2063520635
integrity sha512-ocyWc3bAHBB/guyqJQVI5o4BZkPhznPYUG2ea80Gond/BgNWpap8TOmLSeeQG7bnh2KMISxskdADG59j7zruhw==
2063620636

20637-
valibot@^0.36.0:
20638-
version "0.36.0"
20639-
resolved "https://registry.npmjs.org/valibot/-/valibot-0.36.0.tgz"
20640-
integrity sha512-CjF1XN4sUce8sBK9TixrDqFM7RwNkuXdJu174/AwmQUB62QbCQADg5lLe8ldBalFgtj1uKj+pKwDJiNo4Mn+eQ==
20637+
valibot@1.2.0, valibot@^0.36.0:
20638+
version "1.2.0"
20639+
resolved "https://registry.npmjs.org/valibot/-/valibot-1.2.0.tgz#8fc720d9e4082ba16e30a914064a39619b2f1d6f"
20640+
integrity sha512-mm1rxUsmOxzrwnX5arGS+U4T25RdvpPjPN4yR0u9pUBov9+zGVtO84tif1eY4r6zWxVxu3KzIyknJy3rxfRZZg==
2064120641

2064220642
validate-npm-package-license@3.0.4, validate-npm-package-license@^3.0.1, validate-npm-package-license@^3.0.4:
2064320643
version "3.0.4"
@@ -20657,10 +20657,10 @@ validate-npm-package-name@^5.0.0:
2065720657
resolved "https://registry.npmjs.org/validate-npm-package-name/-/validate-npm-package-name-5.0.1.tgz"
2065820658
integrity sha512-OljLrQ9SQdOUqTaQxqL5dEfZWrXExyyWsozYlAWFawPVNuD83igl7uJD2RTkNMbniIYgt8l81eCJGIdQF7avLQ==
2065920659

20660-
validator@^13.7.0:
20661-
version "13.15.15"
20662-
resolved "https://registry.npmjs.org/validator/-/validator-13.15.15.tgz"
20663-
integrity sha512-BgWVbCI72aIQy937xbawcs+hrVaN/CZ2UwutgaJ36hGqRrLNM+f5LUT/YPRbo8IV/ASeFzXszezV+y2+rq3l8A==
20660+
validator@13.15.23, validator@^13.7.0:
20661+
version "13.15.23"
20662+
resolved "https://registry.npmjs.org/validator/-/validator-13.15.23.tgz#59a874f84e4594588e3409ab1edbe64e96d0c62d"
20663+
integrity sha512-4yoz1kEWqUjzi5zsPbAS/903QXSYp0UOtHsPpp7p9rHAw/W+dkInskAE386Fat3oKRROwO98d9ZB0G4cObgUyw==
2066420664

2066520665
varuint-bitcoin@^1.0.1, varuint-bitcoin@^1.0.4, varuint-bitcoin@^1.1.2:
2066620666
version "1.1.2"

0 commit comments

Comments
 (0)