Skip to content

[Snyk] Security upgrade hardhat from 2.8.0 to 2.9.0#7

Open
torjc01 wants to merge 1 commit intomainfrom
snyk-fix-da25f6e3976076b2934f1724103a5e1e
Open

[Snyk] Security upgrade hardhat from 2.8.0 to 2.9.0#7
torjc01 wants to merge 1 commit intomainfrom
snyk-fix-da25f6e3976076b2934f1724103a5e1e

Conversation

@torjc01
Copy link
Owner

@torjc01 torjc01 commented Jul 31, 2022

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NODEFETCH-2964180
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: hardhat The new version differs by 250 commits.
  • dffdfd0 Version Packages
  • 8d2c577 Merge pull request #2422 from NomicFoundation/fix-core-tests
  • 10291cb Merge pull request #2423 from NomicFoundation/dependabot/npm_and_yarn/prismjs-1.27.0
  • 1909666 Merge pull request #2430 from NomicFoundation/dependabot/npm_and_yarn/url-parse-1.5.10
  • 153515e Bump url-parse from 1.5.7 to 1.5.10
  • dd2ee0f Bump prismjs from 1.25.0 to 1.27.0
  • 7188f06 Use a low keepAlive in the tests http provider
  • 9598650 Merge pull request #2414 from NomicFoundation/test-http-provider
  • bd7d4e3 Ensure that TOO_MANY_REQUESTs is rcvd by client
  • 8dcbc21 Use a fresh MockPool for each test case
  • 8074f9d Merge pull request #2419 from NomicFoundation/rm-unnecessary-condition
  • 41282aa compiler downloader: rm unnecessary condition
  • 54e6ffd Merge pull request #2372 from NomicFoundation/parallel
  • 3261621 Merge branch 'master' into parallel
  • 7964d6d comment usage of `disableNetConnect()`
  • 9ddd91f Merge pull request #2370 from NomicFoundation/rm-node-fetch
  • fc49cc5 Add User-Agent to HttpProvider's request
  • b82a80d Download compilers serially
  • fd87504 Add hardhat version to User-Agent
  • b3e607e Merge branch 'master' into rm-node-fetch
  • fd1528f Use a named function, not an IIFE
  • 9ae7643 Rm https-proxy-agent from package.json
  • 8c93508 Add comments explaining body consumption on error
  • a50ad11 Test retry handling with retry-after header

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@netlify
Copy link

netlify bot commented Jul 31, 2022

Deploy Preview for elated-aryabhata-d0c610 ready!

Name Link
🔨 Latest commit b06d9a1
🔍 Latest deploy log https://app.netlify.com/sites/elated-aryabhata-d0c610/deploys/62e6c4b6465e35000a7b039b
😎 Deploy Preview https://deploy-preview-7--elated-aryabhata-d0c610.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants