Skip to content

[Snyk] Security upgrade hardhat from 2.9.3 to 2.10.0#11

Open
snyk-bot wants to merge 1 commit intomainfrom
snyk-fix-d83f3b08846beaa0845ae0af24c9ca6e
Open

[Snyk] Security upgrade hardhat from 2.9.3 to 2.10.0#11
snyk-bot wants to merge 1 commit intomainfrom
snyk-fix-d83f3b08846beaa0845ae0af24c9ca6e

Conversation

@snyk-bot
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOCHA-2863123
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: hardhat The new version differs by 250 commits.
  • c6c547b Update package.json
  • fd11202 Version Packages
  • bcd3225 Merge pull request #2905 from NomicFoundation/next-version
  • 5896e60 Bump network helpers to v1.0.2
  • ced9c94 Bump network helpers to v1.0.1
  • 5b29b0e Add changeset
  • 714225d Fix isValidAddress
  • 36786b5 Merge pull request #2903 from NomicFoundation/pato/hh-886
  • 8e8ee38 Update packages/hardhat-core/src/internal/cli/project-creation.ts
  • ba4a188 Update packages/hardhat-core/src/internal/cli/project-creation.ts
  • 8e4d2ee Merge pull request #2904 from NomicFoundation/tutorial-console-log
  • 3d7e98e Remove unnecessary string interpolation
  • 68fc91a Make console.log usage match the boilerplate
  • e6870e5 Remove early mention of console.log
  • 304329e Match comment with generated config and boilerplate
  • c6094d5 Merge pull request #2867 from NomicFoundation/pato/hh-793
  • 3b30f1f Rephrase fixtures paragraph
  • 2e1f887 Update wording
  • 61ff676 Prompt new users to star our repo
  • f4955f1 Fix linter
  • 0a64eb3 Merge pull request #2902 from focusreactive/fr/hotfix/nav-behavior-docs-page
  • ada1dbd Update docs/src/content/tutorial/testing-contracts.md
  • 3a5b8be Update docs/src/content/tutorial/testing-contracts.md
  • 6df5bce Update docs/src/content/tutorial/testing-contracts.md

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

@netlify
Copy link

netlify bot commented Oct 16, 2022

Deploy Preview for elated-aryabhata-d0c610 ready!

Name Link
🔨 Latest commit 6a8bd5f
🔍 Latest deploy log https://app.netlify.com/sites/elated-aryabhata-d0c610/deploys/634c437f1c63670009058f3c
😎 Deploy Preview https://deploy-preview-11--elated-aryabhata-d0c610.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant