Skip to content

Commit c297acd

Browse files
Merge pull request #6777 from BitGo/WP-5668/fix-advisory-1103747
fix(root): sha.js vulnerability
2 parents 3e354e1 + c3f8820 commit c297acd

File tree

2 files changed

+9
-7
lines changed

2 files changed

+9
-7
lines changed

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,6 +59,7 @@
5959
"yeoman-generator": "^5.6.1"
6060
},
6161
"resolutions": {
62+
"**/sha.js": ">=2.4.12",
6263
"@ethereumjs/util": "8.0.3",
6364
"@types/keyv": "3.1.4",
6465
"@types/react": "17.0.24",
@@ -139,4 +140,4 @@
139140
"tmp": "^0.2.3"
140141
},
141142
"packageManager": "[email protected]"
142-
}
143+
}

yarn.lock

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -18851,13 +18851,14 @@ [email protected]:
1885118851
resolved "https://registry.npmjs.org/setprototypeof/-/setprototypeof-1.2.0.tgz#66c9a24a73f9fc28cbe66b09fed3d33dcaf1b424"
1885218852
integrity sha512-E5LDX7Wrp85Kil5bhZv46j8jOeboKq5JMmYM3gVGdGH8xFpPWXUMsNrlODCrkoxMEeNi/XZIwuRvY4XNwYMJpw==
1885318853

18854-
sha.js@^2.3.6, sha.js@^2.4.0, sha.js@^2.4.11, sha.js@^2.4.8, sha.js@~2.4.4:
18855-
version "2.4.11"
18856-
resolved "https://registry.npmjs.org/sha.js/-/sha.js-2.4.11.tgz#37a5cf0b81ecbc6943de109ba2960d1b26584ae7"
18857-
integrity sha512-QMEp5B7cftE7APOjk5Y6xgrbWu+WkLVQwk8JNjZ8nKRciZaByEW6MubieAiToS7+dwvrjGhH8jRXz3MVd0AYqQ==
18854+
sha.js@>=2.4.12, sha.js@^2.3.6, sha.js@^2.4.0, sha.js@^2.4.11, sha.js@^2.4.8, sha.js@~2.4.4:
18855+
version "2.4.12"
18856+
resolved "https://registry.npmjs.org/sha.js/-/sha.js-2.4.12.tgz#eb8b568bf383dfd1867a32c3f2b74eb52bdbf23f"
18857+
integrity sha512-8LzC5+bvI45BjpfXU8V5fdU2mfeKiQe1D1gIMn7XUlF3OTUrpdJpPPH4EMAnF0DsHHdSZqCdSss5qCmJKuiO3w==
1885818858
dependencies:
18859-
inherits "^2.0.1"
18860-
safe-buffer "^5.0.1"
18859+
inherits "^2.0.4"
18860+
safe-buffer "^5.2.1"
18861+
to-buffer "^1.2.0"
1886118862

1886218863
shallow-clone@^3.0.0:
1886318864
version "3.0.1"

0 commit comments

Comments
 (0)