Skip to content

patch: bumps elliptic version to patch CVE #20

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

Genysys
Copy link

@Genysys Genysys commented Feb 22, 2021

@tperamaki
Copy link

Please update due to CVE-2020-28498 (GHSA-r9p9-mrjm-926w)

@calvinmetcalf

@tmadar
Copy link

tmadar commented Aug 30, 2024

@tperamaki @calvinmetcalf any update of having this be done?

@paulmck21
Copy link

Any update on this?

@wspurgin
Copy link

New GHSA GHSA-vjh7-7g9h-fjfh on elliptic - there's been no release commit in 5 years so I suspect this is a losing battle.

The very ubiquitious node-stdlib-browser relies on crypto-browserify which relies on this package. Reminds me of the classic dependency xkcd

@soufianechalouh
Copy link

@paulmck21 @wspurgin Any alternative forks you came across?

@wspurgin
Copy link

wspurgin commented Apr 9, 2025

@paulmck21 @wspurgin Any alternative forks you came across?

Just pnpm overrides to force the use of a patched version of elliptic.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants