Skip to content

Commit c14867d

Browse files
chore(deps): fix dependabot security alerts (#326)
Update vulnerable dependencies via overrides/resolutions: - h3: 1.15.5 (fixes CVE in multiple dapps) - node-forge: 1.3.3 (fixes security vulnerability) - undici: 6.23.0 (fixes security vulnerability) - js-yaml: 4.1.1 (fixes security vulnerability) - glob: 10.5.0 (fixes security vulnerability) - aws-sdk-s3: 1.211.0 (Ruby/fastlane dependency) Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
1 parent 02bd4e6 commit c14867d

File tree

17 files changed

+755
-526
lines changed

17 files changed

+755
-526
lines changed

Gemfile.lock

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -25,28 +25,28 @@ GEM
2525
artifactory (3.0.17)
2626
atomos (0.1.3)
2727
aws-eventstream (1.4.0)
28-
aws-partitions (1.1147.0)
29-
aws-sdk-core (3.229.0)
28+
aws-partitions (1.1205.0)
29+
aws-sdk-core (3.241.3)
3030
aws-eventstream (~> 1, >= 1.3.0)
3131
aws-partitions (~> 1, >= 1.992.0)
3232
aws-sigv4 (~> 1.9)
3333
base64
3434
bigdecimal
3535
jmespath (~> 1, >= 1.6.1)
3636
logger
37-
aws-sdk-kms (1.110.0)
38-
aws-sdk-core (~> 3, >= 3.228.0)
37+
aws-sdk-kms (1.120.0)
38+
aws-sdk-core (~> 3, >= 3.241.3)
3939
aws-sigv4 (~> 1.5)
40-
aws-sdk-s3 (1.196.1)
41-
aws-sdk-core (~> 3, >= 3.228.0)
40+
aws-sdk-s3 (1.211.0)
41+
aws-sdk-core (~> 3, >= 3.241.3)
4242
aws-sdk-kms (~> 1)
4343
aws-sigv4 (~> 1.5)
4444
aws-sigv4 (1.12.1)
4545
aws-eventstream (~> 1, >= 1.0.2)
4646
babosa (1.0.4)
4747
base64 (0.3.0)
4848
benchmark (0.4.1)
49-
bigdecimal (3.1.7)
49+
bigdecimal (4.0.1)
5050
claide (1.1.0)
5151
cocoapods (1.14.3)
5252
addressable (~> 2.8)

dapps/ModalEthers/package.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -76,7 +76,8 @@
7676
"on-headers": "1.1.0",
7777
"brace-expansion": "1.1.12",
7878
"fast-redact": "3.5.0",
79-
"node-forge": "1.3.2",
80-
"js-yaml": "4.1.1"
79+
"node-forge": "1.3.3",
80+
"js-yaml": "4.1.1",
81+
"h3": "1.15.5"
8182
}
8283
}

dapps/ModalEthers/yarn.lock

Lines changed: 52 additions & 45 deletions
Original file line numberDiff line numberDiff line change
@@ -3668,10 +3668,10 @@ convert-source-map@^2.0.0:
36683668
resolved "https://registry.yarnpkg.com/convert-source-map/-/convert-source-map-2.0.0.tgz#4b560f649fc4e918dd0ab75cf4961e8bc882d82a"
36693669
integrity sha512-Kvp459HrV2FEJ1CAsi1Ku+MY3kasH19TFykTz2xWmMeq6bk2NU3XXvfJ+Q61m0xktWwt+1HSYf3JZsTms3aRJg==
36703670

3671-
cookie-es@^1.0.0:
3672-
version "1.0.0"
3673-
resolved "https://registry.yarnpkg.com/cookie-es/-/cookie-es-1.0.0.tgz#4759684af168dfc54365b2c2dda0a8d7ee1e4865"
3674-
integrity sha512-mWYvfOLrfEc996hlKcdABeIiPHUPC6DM2QYZdGGOvhOTbA3tjm2eBwqlJpoFdjC89NI4Qt6h0Pu06Mp+1Pj5OQ==
3671+
cookie-es@^1.2.2:
3672+
version "1.2.2"
3673+
resolved "https://registry.yarnpkg.com/cookie-es/-/cookie-es-1.2.2.tgz#18ceef9eb513cac1cb6c14bcbf8bdb2679b34821"
3674+
integrity sha512-+W7VmiVINB+ywl1HGXJXmrqkOhpKrIiVZV6tQuV54ZyQC7MMuBt81Vc336GMLoHBq5hV/F9eXgt5Mnx0Rha5Fg==
36753675

36763676
core-js-compat@^3.31.0:
36773677
version "3.32.2"
@@ -3724,6 +3724,13 @@ cross-spawn@^7.0.2, cross-spawn@^7.0.3, cross-spawn@^7.0.6:
37243724
shebang-command "^2.0.0"
37253725
which "^2.0.1"
37263726

3727+
crossws@^0.3.5:
3728+
version "0.3.5"
3729+
resolved "https://registry.yarnpkg.com/crossws/-/crossws-0.3.5.tgz#daad331d44148ea6500098bc858869f3a5ab81a6"
3730+
integrity sha512-ojKiDvcmByhwa8YYqbQI/hg7MEU0NC03+pSdEq4ZUnZR9xXpwk7E43SMNGkn+JxJGPFtNvQ48+vV2p+P1ml5PA==
3731+
dependencies:
3732+
uncrypto "^0.1.3"
3733+
37273734
css-select@^5.1.0:
37283735
version "5.1.0"
37293736
resolved "https://registry.yarnpkg.com/css-select/-/css-select-5.1.0.tgz#b8ebd6554c3637ccc76688804ad3f6a6fdaea8a6"
@@ -3829,7 +3836,7 @@ define-properties@^1.1.3, define-properties@^1.1.4, define-properties@^1.2.0, de
38293836
has-property-descriptors "^1.0.0"
38303837
object-keys "^1.1.1"
38313838

3832-
defu@^6.1.3, defu@^6.1.4:
3839+
defu@^6.1.4:
38333840
version "6.1.4"
38343841
resolved "https://registry.yarnpkg.com/defu/-/defu-6.1.4.tgz#4e0c9cf9ff68fe5f3d7f2765cc1a012dfdcb0479"
38353842
integrity sha512-mEQCMmwJu317oSz8CwdIOdwf3xMif1ttiM8LTufzc3g6kR+9Pe236twL8j3IYT1F7GfRgGcW6MWxzZjLIkuHIg==
@@ -3863,6 +3870,11 @@ destr@^2.0.1, destr@^2.0.2:
38633870
resolved "https://registry.yarnpkg.com/destr/-/destr-2.0.2.tgz#8d3c0ee4ec0a76df54bc8b819bca215592a8c218"
38643871
integrity sha512-65AlobnZMiCET00KaFFjUefxDX0khFA/E4myqZ7a6Sq1yZtR8+FVIvilVX66vF2uobSumxooYZChiRPCKNqhmg==
38653872

3873+
destr@^2.0.5:
3874+
version "2.0.5"
3875+
resolved "https://registry.yarnpkg.com/destr/-/destr-2.0.5.tgz#7d112ff1b925fb8d2079fac5bdb4a90973b51fdb"
3876+
integrity sha512-ugFTXCtDZunbzasqBxrK93Ik/DRYsO6S/fedkWEMKqt04xZ4csmnmwGDBAb07QWNaGMAmnTIemsYZCksjATwsA==
3877+
38663878
destroy@1.2.0:
38673879
version "1.2.0"
38683880
resolved "https://registry.yarnpkg.com/destroy/-/destroy-1.2.0.tgz#4803735509ad8be552934c67df614f94e66fa015"
@@ -4791,19 +4803,20 @@ graphemer@^1.4.0:
47914803
resolved "https://registry.yarnpkg.com/graphemer/-/graphemer-1.4.0.tgz#fb2f1d55e0e3a1849aeffc90c4fa0dd53a0e66c6"
47924804
integrity sha512-EtKwoO6kxCL9WO5xipiHTZlSzBm7WLT627TqC/uVRd0HKmq8NXyebnNYxDoBi7wt8eTWrUrKXCOVaFq9x1kgag==
47934805

4794-
h3@^1.10.0, h3@^1.8.2:
4795-
version "1.10.0"
4796-
resolved "https://registry.yarnpkg.com/h3/-/h3-1.10.0.tgz#55ac36deb6e250ada5ff1940b6324bc6acc4085f"
4797-
integrity sha512-Tw1kcIC+AeimwRmviiObaD5EB430Yt+lTgOxLJxNr96Vd/fGRu04EF7aKfOAcpwKCI+U2JlbxOLhycD86p3Ciw==
4806+
h3@1.15.5, h3@^1.10.0, h3@^1.8.2:
4807+
version "1.15.5"
4808+
resolved "https://registry.yarnpkg.com/h3/-/h3-1.15.5.tgz#e2f28d4a66a249973bb050eaddb06b9ab55506f8"
4809+
integrity sha512-xEyq3rSl+dhGX2Lm0+eFQIAzlDN6Fs0EcC4f7BNUmzaRX/PTzeuM+Tr2lHB8FoXggsQIeXLj8EDVgs5ywxyxmg==
47984810
dependencies:
4799-
cookie-es "^1.0.0"
4800-
defu "^6.1.3"
4801-
destr "^2.0.2"
4802-
iron-webcrypto "^1.0.0"
4803-
radix3 "^1.1.0"
4804-
ufo "^1.3.2"
4811+
cookie-es "^1.2.2"
4812+
crossws "^0.3.5"
4813+
defu "^6.1.4"
4814+
destr "^2.0.5"
4815+
iron-webcrypto "^1.2.1"
4816+
node-mock-http "^1.0.4"
4817+
radix3 "^1.1.2"
4818+
ufo "^1.6.3"
48054819
uncrypto "^0.1.3"
4806-
unenv "^1.8.0"
48074820

48084821
has-bigints@^1.0.1, has-bigints@^1.0.2:
48094822
version "1.0.2"
@@ -5018,10 +5031,10 @@ ip@^1.1.5, ip@^2.0.1:
50185031
resolved "https://registry.yarnpkg.com/ip/-/ip-2.0.1.tgz#e8f3595d33a3ea66490204234b77636965307105"
50195032
integrity sha512-lJUL9imLTNi1ZfXT+DU6rBBdbiKGBuay9B6xGSPVjUeQwaH1RIGqef8RZkUtHioLmSNpPR5M4HVKJGm1j8FWVQ==
50205033

5021-
iron-webcrypto@^1.0.0:
5022-
version "1.0.0"
5023-
resolved "https://registry.yarnpkg.com/iron-webcrypto/-/iron-webcrypto-1.0.0.tgz#e3b689c0c61b434a0a4cb82d0aeabbc8b672a867"
5024-
integrity sha512-anOK1Mktt8U1Xi7fCM3RELTuYbnFikQY5VtrDj7kPgpejV7d43tWKhzgioO0zpkazLEL/j/iayRqnJhrGfqUsg==
5034+
iron-webcrypto@^1.2.1:
5035+
version "1.2.1"
5036+
resolved "https://registry.yarnpkg.com/iron-webcrypto/-/iron-webcrypto-1.2.1.tgz#aa60ff2aa10550630f4c0b11fd2442becdb35a6f"
5037+
integrity sha512-feOM6FaSr6rEABp/eDfVseKyTMDt+KGpeB35SkVn9Tyn0CqvVsY3EwI0v5i8nMHyJnzCIQf7nsy3p41TPkJZhg==
50255038

50265039
is-array-buffer@^3.0.1, is-array-buffer@^3.0.2:
50275040
version "3.0.2"
@@ -6672,11 +6685,6 @@ mime@^2.4.1:
66726685
resolved "https://registry.yarnpkg.com/mime/-/mime-2.6.0.tgz#a2a682a95cd4d0cb1d6257e28f83da7e35800367"
66736686
integrity sha512-USPkMeET31rOMiarsBNIHZKLGgvKc/LrjofAnBlOttf5ajRvqiRA8QsenbcooctK6d6Ts6aqZXBA+XbkKthiQg==
66746687

6675-
mime@^3.0.0:
6676-
version "3.0.0"
6677-
resolved "https://registry.yarnpkg.com/mime/-/mime-3.0.0.tgz#b374550dca3a0c18443b0c950a6a58f1931cf7a7"
6678-
integrity sha512-jSCU7/VB1loIWBZe14aEYHU/+1UMEHoaO7qxCOVJOw9GgH72VAWppxNcjU+x9a2k3GSIBXNKxXQFqRvvZ7vr3A==
6679-
66806688
mimic-fn@^2.1.0:
66816689
version "2.1.0"
66826690
resolved "https://registry.yarnpkg.com/mimic-fn/-/mimic-fn-2.1.0.tgz#7ed2c2ccccaf84d3ffcb7a69b57711fc2083401b"
@@ -6828,7 +6836,7 @@ node-dir@^0.1.17:
68286836
dependencies:
68296837
minimatch "^3.0.2"
68306838

6831-
node-fetch-native@^1.4.0, node-fetch-native@^1.4.1, node-fetch-native@^1.6.1:
6839+
node-fetch-native@^1.4.0, node-fetch-native@^1.4.1:
68326840
version "1.6.1"
68336841
resolved "https://registry.yarnpkg.com/node-fetch-native/-/node-fetch-native-1.6.1.tgz#f95c74917d3cebc794cdae0cd2a9c7594aad0cb4"
68346842
integrity sha512-bW9T/uJDPAJB2YNYEpWzE54U5O3MQidXsOyTfnbKYtTtFexRvGzb1waphBN4ZwP6EcIvYYEOwW0b72BpAqydTw==
@@ -6840,16 +6848,21 @@ node-fetch@^2.2.0, node-fetch@^2.6.0, node-fetch@^2.6.1, node-fetch@^2.6.12:
68406848
dependencies:
68416849
whatwg-url "^5.0.0"
68426850

6843-
node-forge@1.3.2, node-forge@^1.3.1:
6844-
version "1.3.2"
6845-
resolved "https://registry.yarnpkg.com/node-forge/-/node-forge-1.3.2.tgz#d0d2659a26eef778bf84d73e7f55c08144ee7750"
6846-
integrity sha512-6xKiQ+cph9KImrRh0VsjH2d8/GXA4FIMlgU4B757iI1ApvcyA9VlouP0yZJha01V+huImO+kKMU7ih+2+E14fw==
6851+
node-forge@1.3.3, node-forge@^1.3.1:
6852+
version "1.3.3"
6853+
resolved "https://registry.yarnpkg.com/node-forge/-/node-forge-1.3.3.tgz#0ad80f6333b3a0045e827ac20b7f735f93716751"
6854+
integrity sha512-rLvcdSyRCyouf6jcOIPe/BgwG/d7hKjzMKOas33/pHEr6gbq18IK9zV7DiPvzsz0oBJPme6qr6H6kGZuI9/DZg==
68476855

68486856
node-int64@^0.4.0:
68496857
version "0.4.0"
68506858
resolved "https://registry.yarnpkg.com/node-int64/-/node-int64-0.4.0.tgz#87a9065cdb355d3182d8f94ce11188b825c68a3b"
68516859
integrity sha512-O5lz91xSOeoXP6DulyHfllpq+Eg00MWitZIbtPfoSEvqIHdl5gfcY6hYzDWnj0qD5tz52PI08u9qUvSVeUBeHw==
68526860

6861+
node-mock-http@^1.0.4:
6862+
version "1.0.4"
6863+
resolved "https://registry.yarnpkg.com/node-mock-http/-/node-mock-http-1.0.4.tgz#21f2ab4ce2fe4fbe8a660d7c5195a1db85e042a4"
6864+
integrity sha512-8DY+kFsDkNXy1sJglUfuODx1/opAGJGyrTuFqEoN90oRc2Vk0ZbD4K2qmKXBBEhZQzdKHIVfEJpDU8Ak2NJEvQ==
6865+
68536866
node-releases@^2.0.13:
68546867
version "2.0.13"
68556868
resolved "https://registry.yarnpkg.com/node-releases/-/node-releases-2.0.13.tgz#d5ed1627c23e3461e819b02e57b75e4899b1c81d"
@@ -7359,10 +7372,10 @@ quick-format-unescaped@^4.0.3:
73597372
resolved "https://registry.yarnpkg.com/quick-format-unescaped/-/quick-format-unescaped-4.0.4.tgz#93ef6dd8d3453cbc7970dd614fad4c5954d6b5a7"
73607373
integrity sha512-tYC1Q1hgyRuHgloV/YXs2w15unPVh8qfu/qCTfhTYamaw7fyhumKa2yGpdSo87vY32rIclj+4fWYQXUMs9EHvg==
73617374

7362-
radix3@^1.1.0:
7363-
version "1.1.0"
7364-
resolved "https://registry.yarnpkg.com/radix3/-/radix3-1.1.0.tgz#9745df67a49c522e94a33d0a93cf743f104b6e0d"
7365-
integrity sha512-pNsHDxbGORSvuSScqNJ+3Km6QAVqk8CfsCBIEoDgpqLrkD2f3QM4I7d1ozJJ172OmIcoUcerZaNWqtLkRXTV3A==
7375+
radix3@^1.1.2:
7376+
version "1.1.2"
7377+
resolved "https://registry.yarnpkg.com/radix3/-/radix3-1.1.2.tgz#fd27d2af3896c6bf4bcdfab6427c69c2afc69ec0"
7378+
integrity sha512-b484I/7b8rDEdSDKckSSBA8knMpcdsXudlE/LNL639wFoHKwLbEkQFZHWEYwDC0wa0FKUcCY+GAF73Z7wxNVFA==
73667379

73677380
range-parser@~1.2.1:
73687381
version "1.2.1"
@@ -8346,6 +8359,11 @@ ufo@^1.3.0, ufo@^1.3.1, ufo@^1.3.2:
83468359
resolved "https://registry.yarnpkg.com/ufo/-/ufo-1.3.2.tgz#c7d719d0628a1c80c006d2240e0d169f6e3c0496"
83478360
integrity sha512-o+ORpgGwaYQXgqGDwd+hkS4PuZ3QnmqMMxRuajK/a38L6fTpcE5GPIfrf+L/KemFzfUpeUQc1rRS1iDBozvnFA==
83488361

8362+
ufo@^1.6.3:
8363+
version "1.6.3"
8364+
resolved "https://registry.yarnpkg.com/ufo/-/ufo-1.6.3.tgz#799666e4e88c122a9659805e30b9dc071c3aed4f"
8365+
integrity sha512-yDJTmhydvl5lJzBmy/hyOAA0d+aqCBuwl818haVdYCRrWV84o7YyeVm4QlVHStqNrrJSTb6jKuFAVqAFsr+K3Q==
8366+
83498367
uglify-es@^3.1.9:
83508368
version "3.3.9"
83518369
resolved "https://registry.yarnpkg.com/uglify-es/-/uglify-es-3.3.9.tgz#0c1c4f0700bed8dbc124cdb304d2592ca203e677"
@@ -8376,17 +8394,6 @@ uncrypto@^0.1.3:
83768394
resolved "https://registry.yarnpkg.com/uncrypto/-/uncrypto-0.1.3.tgz#e1288d609226f2d02d8d69ee861fa20d8348ef2b"
83778395
integrity sha512-Ql87qFHB3s/De2ClA9e0gsnS6zXG27SkTiSJwjCc9MebbfapQfuPzumMIUMi38ezPZVNFcHI9sUIepeQfw8J8Q==
83788396

8379-
unenv@^1.8.0:
8380-
version "1.9.0"
8381-
resolved "https://registry.yarnpkg.com/unenv/-/unenv-1.9.0.tgz#469502ae85be1bd3a6aa60f810972b1a904ca312"
8382-
integrity sha512-QKnFNznRxmbOF1hDgzpqrlIf6NC5sbZ2OJ+5Wl3OX8uM+LUJXbj4TXvLJCtwbPTmbMHCLIz6JLKNinNsMShK9g==
8383-
dependencies:
8384-
consola "^3.2.3"
8385-
defu "^6.1.3"
8386-
mime "^3.0.0"
8387-
node-fetch-native "^1.6.1"
8388-
pathe "^1.1.1"
8389-
83908397
unfetch@^4.2.0:
83918398
version "4.2.0"
83928399
resolved "https://registry.yarnpkg.com/unfetch/-/unfetch-4.2.0.tgz#7e21b0ef7d363d8d9af0fb929a5555f6ef97a3be"

dapps/ModalUProvider/package.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,8 @@
6666
"on-headers": "1.1.0",
6767
"brace-expansion": "1.1.12",
6868
"fast-redact": "3.5.0",
69-
"node-forge": "1.3.2",
70-
"js-yaml": "4.1.1"
69+
"node-forge": "1.3.3",
70+
"js-yaml": "4.1.1",
71+
"h3": "1.15.5"
7172
}
7273
}

0 commit comments

Comments
 (0)