Skip to content

Conversation

fusmanii
Copy link
Contributor

@fusmanii fusmanii commented Sep 4, 2025

Vulnerability in sha.js <= 2.4.11 GHSA-95m3-7q98-8xr5

Signed-off-by: Faisal Usmani <[email protected]>
@fusmanii fusmanii force-pushed the faisal/update-sha-js branch from bd89e30 to a82c50c Compare September 4, 2025 14:04
"**/eth-crypto/secp256k1": "5.0.1"
"**/eth-crypto/secp256k1": "5.0.1",
"**/create-hash/sha.js": "2.4.12",
"sha.js": "2.4.12"
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we know where this outdated version comes from? If it's in the uma repo we should probably go upstream and fix it there so we don't need to override the resolution.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It looks like its coming from ethereum-cryptography which ethereumjs-util depends on

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we are at latest version of ethereumjs-util already, so I think we need the resolution until they patch on their end

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants