Skip to content

Fix audit ci pipeline#419

Open
TucksonDev wants to merge 1 commit intodevelopfrom
fix-advisories
Open

Fix audit ci pipeline#419
TucksonDev wants to merge 1 commit intodevelopfrom
fix-advisories

Conversation

@TucksonDev
Copy link
Copy Markdown
Contributor

Advisories added:

  • GHSA-43fc-jf86-j433: Axios is Vulnerable to Denial of Service via proto Key in mergeConfig (axios is a dependency of hardhat-deploy and hardhat-gas-reporter)
  • GHSA-378v-28hj-76wf: bn.js affected by an infinite loop (bn.js is a dependency of ethers, which is a dependency of hardhat)
  • GHSA-5c6j-r48x-rmvq: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() (serialize-javascript is a dependency of mocha, which is a dependency of hardhat)
  • GHSA-2mjp-6q6p-2qxm: Undici has an HTTP Request/Response Smuggling issue (undici is a dependency of hardhat and hardhat-verify)
  • GHSA-vrm6-8vpv-qv8q: Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression (undici is a dependency of hardhat and hardhat-verify)
  • GHSA-v9p9-hfj2-hcw8: Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation (undici is a dependency of hardhat and hardhat-verify)
  • GHSA-4992-7rv2-5pvq: Undici has CRLF Injection in undici via upgrade option (undici is a dependency of hardhat and hardhat-verify)
  • GHSA-xxjr-mmjv-4gpg: Lodash has Prototype Pollution Vulnerability in _.unset and _.omit functions (lodash is a dependency of synp, which is a dependency of yarn-audit-fix)
  • GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using $data option (ajv is a dependency of hardhat)

Packages updated:

  • eslint-config-prettier
  • eslint-plugin-prettier
  • prettier-plugin-solidity
  • solidity-coverage

Direct dependencies with updated indirect dependencies

Direct dependency Updated indirect dependencies
eslint @eslint-community/eslint-utils, @eslint-community/regexpp, acorn, esquery, fastq, flatted
@typescript-eslint/eslint-plugin @eslint-community/regexpp, @types/semver
eslint-plugin-prettier prettier-linter-helpers
ethers bn.js
hardhat @noble/hashes, bn.js, brace-expansion, diff, fastq, follow-redirects, immutable, is-core-module, minimatch, resolve, undici-types
hardhat-deploy axios, follow-redirects, form-data, qs
hardhat-gas-reporter @noble/hashes, @solidity-parser/parser, axios, follow-redirects, form-data
hardhat-ignore-warnings brace-expansion, minimatch
solhint @solidity-parser/parser, brace-expansion, minimatch
solidity-coverage @noble/hashes, @types/minimatch, balanced-match, bn.js, brace-expansion, chalk, fastq, is-core-module, jsonfile, minimatch, resolve
tslint @babel/code-frame, @babel/helper-validator-identifier, chalk
typechain chalk
yarn-audit-fix @types/lodash, @types/semver, chalk, lodash-es, lodash

@TucksonDev TucksonDev changed the base branch from main to develop March 17, 2026 12:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant