js icon indicating copy to clipboard operation
js copied to clipboard

3 severe vulnerability and can not fix with audit fix

Open cSarcasme opened this issue 1 year ago • 0 comments

3 severe vulnerability and can not fix with audit fix

crypto-js <4.2.0 Severity: critical crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard - https://github.com/advisories/GHSA-xwcq-pm8m-c4vf fix available via npm audit fix --force Will install @metaplex-foundation/[email protected], which is a breaking change node_modules/crypto-js merkletreejs >=0.0.9 Depends on vulnerable versions of crypto-js node_modules/merkletreejs @metaplex-foundation/js >=0.17.0 Depends on vulnerable versions of merkletreejs node_modules/@metaplex-foundation/js

3 critical severity vulnerabilities

ANd no possibility to use with --force becaus it will do breaking change and create malfunction

In the wait of solution i wish you a good day

cSarcasme avatar Oct 26 '23 12:10 cSarcasme