weshnet icon indicating copy to clipboard operation
weshnet copied to clipboard

chore: upgrade ipfs deps

Open n0izn0iz opened this issue 2 years ago • 4 comments

n0izn0iz avatar Nov 18 '23 19:11 n0izn0iz

:warning: We detected 14 security issues in this pull request:

Vulnerable Libraries (14)
Severity Details
Critical pkg:golang/github.com/libp2p/[email protected] upgrade to: > v0.24.4
High pkg:golang/go.uber.org/[email protected] upgrade to: > v1.2.1
High pkg:golang/golang.org/x/[email protected] upgrade to: > v0.14.0
High pkg:golang/golang.org/x/[email protected] upgrade to: > v0.14.0
High pkg:golang/go.uber.org/[email protected] upgrade to: > v1.26.0
Critical pkg:golang/github.com/libp2p/[email protected] upgrade to: > v0.32.1
Critical pkg:golang/github.com/ipfs/[email protected] upgrade to: > v0.24.0
High pkg:golang/github.com/multiformats/[email protected] upgrade to: > v0.12.0
Critical pkg:golang/github.com/libp2p/[email protected] upgrade to: > v0.10.0
High pkg:golang/github.com/ipfs/[email protected] upgrade to: > v0.1.0
High pkg:golang/google.golang.org/[email protected] upgrade to: > v1.56.3
Critical pkg:golang/github.com/ipfs/[email protected] upgrade to: > v0.15.0
High pkg:golang/github.com/stretchr/[email protected] upgrade to: > v1.8.4
High pkg:golang/github.com/prometheus/[email protected] upgrade to: > v1.17.0

More info on how to fix Vulnerable Libraries in Go.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

guardrails[bot] avatar Nov 18 '23 19:11 guardrails[bot]

Hi @n0izn0iz . Do you have feedback on the message from guardrails? "We detected 14 security issues" https://github.com/berty/weshnet/pull/95#issuecomment-1817613232

jefft0 avatar Nov 20 '23 08:11 jefft0

the tests are not passing anyway, and I still have other conflicts and build problems when integrating in teritori, so this can be marked as stale for now

n0izn0iz avatar Nov 20 '23 12:11 n0izn0iz

@D4ryl00 has already updated libp2p go-ipfs-log and go-orbit-db. He is currently working on a separate PR to update weshnet. If that is merged, we will presumably be able to close this PR.

jefft0 avatar Jul 26 '24 11:07 jefft0

done in PR https://github.com/berty/weshnet/pull/100

D4ryl00 avatar Oct 17 '24 22:10 D4ryl00