dec-todo
                                
                                 dec-todo copied to clipboard
                                
                                    dec-todo copied to clipboard
                            
                            
                            
                        [Snyk] Security upgrade web3 from 1.10.3 to 4.0.1
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
 
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity | 
|---|---|---|---|---|
|  | 646/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 6.5 | Server-side Request Forgery (SSRF) SNYK-JS-REQUEST-3361831 | Yes | Proof of Concept | 
|  | 646/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 6.5 | Prototype Pollution SNYK-JS-TOUGHCOOKIE-5672873 | Yes | Proof of Concept | 
|  | 586/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 5.3 | Regular Expression Denial of Service (ReDoS) SNYK-JS-WS-1296835 | Yes | Proof of Concept | 
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: web3
The new version differs by 250 commits.- 5b5bf87 changelog updates
- 45d55c3 version update
- 4358140 Release/4.0.1 rc.2 (#6152)
- cdc2835 fix canary auth (#6151)
- 55a4de1 add util polyfill (#6150)
- 45edf3d Canary releases (#6143)
- 01ce365 Proposal for rearranging docs (#6141)
- 86082bc skip '### Breaking Changes' section from unreleasedSection array (#6138)
- d60c285 Fix plugin example tests with `4.0.1-rc.1` (#6134)
- 88ac791 Correct and enhance documentation for subscribing to events (#6129)
- daaaff7 Autotype for contract methods (#6137)
- ab80131 support ESM builds (#6131)
- 6202d1e min build whitelisting (#6132)
- 7a924db migration guide update (#6130)
- 4f423fc Fix validation of nested tuples (#6125)
- 408332d fix!: remove non read-only ens methods (#6084)
- 8c5ea34 Providers Tutorial (#6095)
- f2abd6a Eth turorial (#6120)
- 210455a transaction integration tests (#6071)
- fe959a1 Contract options fix (#6118)
- bf1311f update docs so web is imported by default (#6112)
- 3b95b5e fix estimateGas to accept hex data without 0x prefix (#6103)
- 8c3a17b Add a tutorial for smart contract basic interaction (#6089)
- edc7a84 `defaultTransactionTypeParser` Refactor (#6102)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:  
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Server-side Request Forgery (SSRF) 🦉 Prototype Pollution 🦉 Regular Expression Denial of Service (ReDoS)