chatGPTBox icon indicating copy to clipboard operation
chatGPTBox copied to clipboard

Manually update elliptic to v6.5.7 for security update

Open PeterDaveHello opened this issue 1 year ago • 0 comments

Use npm audit fix to update one dependency in the lock.

elliptic v2.0.0 - 6.5.6 affected:

  • Elliptic's ECDSA missing check for whether leading bit of r and s is zero - https://github.com/advisories/GHSA-977x-g7h5-7qgw
  • Elliptic's EDDSA missing signature length check - https://github.com/advisories/GHSA-f7q4-pwc6-w24p
  • Elliptic allows BER-encoded signatures - https://github.com/advisories/GHSA-49q7-c7j4-3p7m

PeterDaveHello avatar Aug 14 '24 16:08 PeterDaveHello