contracts icon indicating copy to clipboard operation
contracts copied to clipboard

❄️ Graph Horizon and Subgraph Service ❄️

Open pcarranzav opened this issue 1 year ago • 4 comments
trafficstars

pcarranzav avatar Feb 20 '24 12:02 pcarranzav

❄️ Graph Horizon and Subgraph Service ❄️

Generated at commit: 1eb425080df31143186e0f60606c57d7e9fd93ca

🚨 Report Summary

Severity Level Results
Contracts Critical High Medium Low Note Total 2 4 0 15 39 60
Dependencies Critical High Medium Low Note Total 0 0 0 0 0 0

For more details view the full report in OpenZeppelin Code Inspector

openzeppelin-code[bot] avatar Feb 20 '24 12:02 openzeppelin-code[bot]

[!WARNING] Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
@openzeppelin/[email protected] has a Critical CVE.

CVE: GHSA-fg47-3c2x-m2wr TimelockController vulnerability in OpenZeppelin Contracts (CRITICAL)

Affected versions: >= 4.0.0 < 4.3.1; >= 3.3.0 < 3.4.2

Patched version: 3.4.2

From: packages/contracts/package.jsonnpm/@openzeppelin/[email protected]

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@openzeppelin/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

socket-security[bot] avatar Feb 21 '24 20:02 socket-security[bot]

Codecov Report

:x: Patch coverage is 86.76471% with 9 lines in your changes missing coverage. Please review. :white_check_mark: Project coverage is 82.84%. Comparing base (cbda0fc) to head (1eb4250). :warning: Report is 665 commits behind head on main.

Files with missing lines Patch % Lines
...ges/contracts/contracts/rewards/RewardsManager.sol 82.14% 5 Missing :warning:
...ges/contracts/contracts/l2/curation/L2Curation.sol 50.00% 2 Missing :warning:
packages/contracts/contracts/staking/Staking.sol 75.00% 2 Missing :warning:
Additional details and impacted files
@@            Coverage Diff             @@
##             main     #944      +/-   ##
==========================================
- Coverage   86.06%   82.84%   -3.22%     
==========================================
  Files          47       47              
  Lines        2074     2093      +19     
  Branches      613      620       +7     
==========================================
- Hits         1785     1734      -51     
- Misses        289      359      +70     
Flag Coverage Δ
unittests 82.84% <86.76%> (-3.22%) :arrow_down:

Flags with carried forward coverage won't be shown. Click here to find out more.

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.

:rocket: New features to boost your workflow:
  • :snowflake: Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • :package: JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

codecov[bot] avatar Feb 21 '24 21:02 codecov[bot]

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​openzeppelin/​contracts@​5.3.0 ⏵ 3.4.110025 -7095 -590100
Added@​types/​json5@​2.2.01001003576100
Added@​openzeppelin/​foundry-upgrades@​0.4.0571009185100
Updated@​graphql-yoga/​plugin-persisted-operations@​3.13.6 ⏵ 3.15.2100 +110066 +398 +3100
Added@​graphprotocol/​sdk@​0.6.0771007288100
Added@​nomicfoundation/​hardhat-foundry@​1.2.0881007390100
Added@​nomicfoundation/​hardhat-toolbox@​4.0.0981007487100
Added@​wagmi/​cli@​2.5.1971007697100
Added@​ethersproject/​providers@​5.7.2991009579100
Added@​nomicfoundation/​ignition-core@​0.15.139910079100100
Added@​typechain/​ethers-v6@​0.5.11001009379100
Added@​typechain/​hardhat@​9.1.010010010080100
Updated@​types/​node@​20.17.58 ⏵ 20.19.14100 +110081 +196100
Updated@​nomicfoundation/​hardhat-network-helpers@​1.0.12 ⏵ 1.1.0100 +110082 +296 -2100
Added@​nomicfoundation/​hardhat-ignition-ethers@​0.15.149910084100100
Added@​nomicfoundation/​hardhat-chai-matchers@​2.1.0991009688100
Updated@​openzeppelin/​contracts-upgradeable@​5.3.0 ⏵ 5.4.0100100 +510090 +1100
Updated@​openzeppelin/​contracts@​5.3.0 ⏵ 5.4.0100100 +510091 +1100
Added@​nomicfoundation/​hardhat-ignition@​0.15.139810091100100
Updated@​eslint/​js@​9.28.0 ⏵ 9.35.010010091 +194 -1100
Updated@​changesets/​cli@​2.29.4 ⏵ 2.29.797 +1100100 +195 +4100
Updatedaxios@​1.9.0 ⏵ 1.12.299100 +1510097 +1100
Added@​nomicfoundation/​hardhat-ethers@​3.0.810010010098100
Added@​nomicfoundation/​hardhat-verify@​2.1.19910010099100
Updated@​typescript-eslint/​eslint-plugin@​8.33.1 ⏵ 8.44.0100 +2100100 +23100 +4100
Updated@​typescript-eslint/​parser@​8.33.1 ⏵ 8.44.0100 +1100100 +32100 +4100

View full report

socket-security[bot] avatar Mar 14 '24 20:03 socket-security[bot]