Skip to content

chore: update dependencies - #106

Open
zachfedor wants to merge 1 commit into
Creit-Tech:mainfrom
theahaco:main
Open

zachfedor wants to merge 1 commit into
Creit-Tech:mainfrom
theahaco:main

Conversation

@zachfedor

Copy link
Copy Markdown
  • What kind of change does this PR introduce?
    Security patch

  • What is the current behavior?
    See Transitive deps pull critical/high vulns on fresh install (protobufjs via @trezor/connect, axios via @reown/@coinbase) #104

  • What is the new behavior (if this is a feature change)?
    Current published version (2.5.0):
    699 pkgs installed → 33 vulns (1 crit, 7 high, 6 mod, 19 low)
    This commit:
    429 pkgs installed → 20 vulns (0 crit, 1 high, 6 mod, 13 low)

  • Other information:
    There's two potential issues left. First, the last high vuln is from axios (@reown/appkit → optional @base-org/account@2.4.0 (hard-pinned) → @coinbase/cdp-sdk → axios@1.16.0). Fix needs ≥1.18.0; appkit 1.8.23 still pins the vulnerable chain. Second, Trezor's v10 line still has no stable release yet. I just bumped from alpha to beta pre-release. Type-checking passes, but I don't have one to test and none of the existing tests cover Trezor functions. You might want to add some mocking for @trezor/connect-web to assert on getAddresses() and signTransaction() to make sure there aren't any API shifts.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant