sui icon indicating copy to clipboard operation
sui copied to clipboard

Update Trustless Swap guide

Open wriches opened this issue 1 year ago • 2 comments

Description

Updated the trustless swap guide to a new reference format

Test plan

Local + Vercel preview

wriches avatar Jun 25 '24 16:06 wriches

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
sui-docs ✅ Ready (Inspect) Visit Preview 💬 Add feedback Jul 2, 2024 2:50am
3 Ignored Deployments
Name Status Preview Comments Updated (UTC)
multisig-toolkit ⬜️ Ignored (Inspect) Visit Preview Jul 2, 2024 2:50am
sui-kiosk ⬜️ Ignored (Inspect) Visit Preview Jul 2, 2024 2:50am
sui-typescript-docs ⬜️ Ignored (Inspect) Visit Preview Jul 2, 2024 2:50am

vercel[bot] avatar Jun 25 '24 16:06 vercel[bot]

Semgrep found 1 ssc-efa14576-9601-4ae6-939c-3da58aa25013 finding:

  • examples/trading/frontend/pnpm-lock.yaml

Risk: Affected versions of vite are vulnerable to Improper Handling Of Case Sensitivity / Exposure Of Sensitive Information To An Unauthorized Actor / Improper Access Control. The vulnerability arises when the Vite development server's option, server.fs.deny, can be circumvented on case-insensitive file systems through the utilization of case-augmented versions of filenames, as the matcher derived from config.server.fs.deny fails to prevent access to sensitive files when raw filesystem paths are requested with augmented casing.

Manual Review Advice: A vulnerability from this advisory is reachable if you host vite's development server on Windows, and you rely on server.fs.deny to deny access to certain files

Fix: Upgrade this library to at least version 4.5.2 at sui/examples/trading/frontend/pnpm-lock.yaml:4700.

Reference(s): https://github.com/advisories/GHSA-c24v-8rfc-w8vw, CVE-2023-34092, CVE-2024-23331

Ignore this finding from ssc-efa14576-9601-4ae6-939c-3da58aa25013.

This PR is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 7 days.

github-actions[bot] avatar Sep 04 '24 01:09 github-actions[bot]