Update elliptic for Improper Verification of Cryptographic Signature.#94
Update elliptic for Improper Verification of Cryptographic Signature.#94ahmedtausif wants to merge 1 commit intobrowserify:mainfrom
Conversation
ljharb
left a comment
There was a problem hiding this comment.
6.6.1 is already in-range for ^6.5.5, so nothing needs to be done except you updating your own lockfiles.
| { | ||
| "name": "browserify-sign", | ||
| "version": "4.2.3", | ||
| "version": "4.2.4", |
There was a problem hiding this comment.
versions should never be updated in PRs, please revert this
|
Will this be released soon? |
|
@Fraraven no, because there’s no need for it. Just update your lockfile. |
|
@ljharb - |
|
Unfortunately not, because noble-curves doesn't support the node versions we do, so it'd be a breaking change. |
Update elliptic for Improper Verification of Cryptographic Signature (https://security.snyk.io/vuln/SNYK-JS-ELLIPTIC-8187303)