Skip to content

[Snyk] Upgrade web3-utils from 1.0.0-beta.34 to 1.7.3#1

Open
cleancoindev wants to merge 1 commit intomasterfrom
snyk-upgrade-6c4f10172d16dd8f6720aedf001f7f61
Open

[Snyk] Upgrade web3-utils from 1.0.0-beta.34 to 1.7.3#1
cleancoindev wants to merge 1 commit intomasterfrom
snyk-upgrade-6c4f10172d16dd8f6720aedf001f7f61

Conversation

@cleancoindev
Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade web3-utils from 1.0.0-beta.34 to 1.7.3.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 80 versions ahead of your current version.
  • The recommended version was released a month ago, on 2022-04-08.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-TRIM-1017038
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept
Information Exposure
SNYK-JS-SIMPLEGET-2361683
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept
Insecure Randomness
npm:cryptiles:20180710
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: web3-utils
  • 1.7.3 - 2022-04-08

    Fixed

    • Fixing build issue of 1.7.2
  • 1.7.3-rc.0 - 2022-04-07

    Fixed

    • Fixing build issue of 1.7.2
  • 1.7.2 - 2022-04-07

    Changed

    • Remove deprecated close event listener (#4825) (#4839)

    Security

    • npm audit fix to update libraries (#4860)

    Fixed

    • Fix jsonrpc payload and response types (#4743) (#4761)
    • Allowed more flexibility in typing the overly constrained provider.disconnect function (#4833)
  • 1.7.2-rc.0 - 2022-03-24

    Changed

    • Remove deprecated close event listener (#4825) (#4839)

    Security

    • npm audit fix to update libraries (#4860)

    Fixed

    • Fix jsonrpc payload and response types (#4743) (#4761)
    • Allowed more flexibility in typing the overly constrained provider.disconnect function (#4833)
  • 1.7.1 - 2022-03-03

    Added

    • transactionPollingInterval added to web3, contract and method constructor options. defaults to 1 second. (#4584)
    • Add example import for package level types (#4611)

    Fixed

    • Fix a typo in the documentation for methods.myMethod.send (#4599)
    • Use globalThis to locate global object if possible (#4613)
    • Fix typos in web3-utils.rst (#4662)
    • Added effectiveGasPrice to TransactionReceipt (#4692)
    • Correction in documentation for web3.eth.accounts.signTransaction (#4576)
    • Updated README to include Webpack 5 create-react-app support instructions (#4173)
    • Update the documentation for methods.myMethod.estimateGas (#4702)
    • Fix typos in REVIEW.md and TESTING.md (#4691)
    • Fix encoding for "0x" string values (#4512)

    Changed

    • Muted E2E gnosis dex tests in CI until fix for issue #4436 is applied (#4701)

    Removed

    • Removed deprecated Morden testnet code (#4339)

    Security

    • Ran npm audit fix to address vulnerabilities and update libraries (#4719) (#4728)
  • 1.7.1-rc.0 - 2022-02-10

    Added

    • transactionPollingInterval added to web3, contract and method constructor options. defaults to 1 second. (#4584)
    • Add example import for package level types (#4611)

    Fixed

    • Fix a typo in the documentation for methods.myMethod.send (#4599)
    • Use globalThis to locate global object if possible (#4613)
    • Fix typos in web3-utils.rst (#4662)
    • Added effectiveGasPrice to TransactionReceipt (#4692)
    • Correction in documentation for web3.eth.accounts.signTransaction (#4576)
    • Updated README to include Webpack 5 create-react-app support instructions (#4173)
    • Update the documentation for methods.myMethod.estimateGas (#4702)
    • Fix typos in REVIEW.md and TESTING.md (#4691)
    • Fix encoding for "0x" string values (#4512)

    Changed

    • Muted E2E gnosis dex tests in CI until fix for issue #4436 is applied (#4701)

    Removed

    • Removed deprecated Morden testnet code (#4339)

    Security

    • Ran npm audit fix to address vulnerabilities and update libraries (#4719) (#4728)
  • 1.7.0 - 2022-01-17

    Added

    • maxPriorityFeePerGas and maxFeePerGas added to Transaction and TransactionConfig interfaces (#4232) (#4585)

    Fixed

    • Fix readthedoc's build for web3js documentation (#4425)
    • Fix response sorting for batch requests (#4250)

    Changed

    • Changed getFeeHistory first parameter type from number to hex according to the spec (#4529)
  • 1.7.0-rc.0 - 2021-12-09

    Added

    • maxPriorityFeePerGas and maxFeePerGas added to Transaction and TransactionConfig interfaces (#4232) (#4585)

    Fixed

    • Fix readthedoc's build for web3js documentation (#4425)
    • Fix response sorting for batch requests (#4250)

    Changed

    • Changed getFeeHistory first parameter type from number to hex according to the spec (#4529)
  • 1.6.1 - 2021-11-15
    Read more
  • 1.6.1-rc.3 - 2021-11-10

    Fixed

    • Correct web3.rst example in documentation (#4511)
    • Correct BlockHeader typing (receiptRoot -> receiptsRoot) (#4452)
  • 1.6.1-rc.2 - 2021-10-27
  • 1.6.1-rc.0 - 2021-10-09
  • 1.6.0 - 2021-09-30
  • 1.6.0-rc.0 - 2021-09-26
  • 1.5.3 - 2021-09-22
  • 1.5.3-rc.0 - 2021-09-10
  • 1.5.2 - 2021-08-15
  • 1.5.2-rc.0 - 2021-08-15
  • 1.5.1 - 2021-08-05
  • 1.5.1-rc.1 - 2021-08-05
  • 1.5.1-rc.0 - 2021-07-31
  • 1.5.0 - 2021-07-28
  • 1.5.0-rc.1 - 2021-07-24
  • 1.5.0-rc.0 - 2021-07-21
  • 1.4.0 - 2021-06-30
  • 1.4.0-rc.0 - 2021-06-25
  • 1.3.6 - 2021-05-14
  • 1.3.6-rc.2 - 2021-05-13
  • 1.3.6-rc.1 - 2021-05-09
  • 1.3.5 - 2021-04-05
  • 1.3.5-rc.0 - 2021-03-24
  • 1.3.4 - 2021-02-03
  • 1.3.4-rc.2 - 2021-01-28
  • 1.3.4-rc.1 - 2021-01-26
  • 1.3.3 - 2021-01-22
  • 1.3.2 - 2021-01-21
  • 1.3.2-rc.2 - 2021-01-21
  • 1.3.1 - 2020-12-17
  • 1.3.0 - 2020-09-15
  • 1.3.0-rc.0 - 2020-09-02
  • 1.2.11 - 2020-07-18
  • 1.2.10 - 2020-07-17
  • 1.2.10-rc.0 - 2020-07-09
  • 1.2.9 - 2020-06-09
  • 1.2.9-rc.0 - 2020-06-02
  • 1.2.8 - 2020-05-20
  • 1.2.8-rc.1 - 2020-05-18
  • 1.2.8-rc.0 - 2020-05-08
  • 1.2.7 - 2020-04-24
  • 1.2.7-rc.0 - 2020-04-15
  • 1.2.6 - 2020-02-02
  • 1.2.5 - 2020-01-27
  • 1.2.5-rc.0 - 2020-01-16
  • 1.2.4 - 2019-11-15
  • 1.2.3 - 2019-11-14
  • 1.2.2 - 2019-10-23
  • 1.2.1 - 2019-08-06
  • 1.2.0 - 2019-07-23
  • 1.0.0 - 2019-07-13
  • 1.0.0-beta.55 - 2019-05-09
  • 1.0.0-beta.54 - 2019-05-02
  • 1.0.0-beta.53 - 2019-04-30
  • 1.0.0-beta.52 - 2019-04-04
  • 1.0.0-beta.51 - 2019-03-28
  • 1.0.0-beta.50 - 2019-03-20
  • 1.0.0-beta.49 - 2019-03-19
  • 1.0.0-beta.48 - 2019-03-05
  • 1.0.0-beta.47 - 2019-03-01
  • 1.0.0-beta.46 - 2019-02-09
  • 1.0.0-beta.45 - 2019-02-09
  • 1.0.0-beta.44 - 2019-02-08
  • 1.0.0-beta.43 - 2019-02-06
  • 1.0.0-beta.42 - 2019-02-06
  • 1.0.0-beta.41 - 2019-01-28
  • 1.0.0-beta.40 - 2019-01-28
  • 1.0.0-beta.39 - 2019-01-27
  • 1.0.0-beta.38 - 2019-01-25
  • 1.0.0-beta.37 - 2018-12-08
  • 1.0.0-beta.36 - 2018-08-27
  • 1.0.0-beta.35 - 2018-07-25
  • 1.0.0-beta.34 - 2018-04-13
from web3-utils GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants