Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: dependency vulnerability fixes #153

Closed

Conversation

benceharomi
Copy link
Contributor

@benceharomi benceharomi commented Jan 3, 2024

What ❔

Upgraded multiple dependencies to avoid using versions with critical or high security vulnerabilities.

@vladbochok
Copy link
Member

@benceharomi Did you fix all dependencies?

I see minimatch has the same version 3.0.4 in the node modules. Do you think we can do something around it?

@StanislavBreadless
Copy link
Collaborator

@vladbochok yes, so basically flat and minimatch are the two dependencies left. They are the dependencies of the hardhat-gas-reporter that we still use

@StanislavBreadless
Copy link
Collaborator

Already included as part of the following release: #167

@benceharomi benceharomi deleted the bh-dependency-vulnerabilities branch February 21, 2024 12:44
@vladbochok vladbochok restored the bh-dependency-vulnerabilities branch April 14, 2024 13:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants