Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feat(contracts)/upgradability #1214

Merged
merged 16 commits into from
Sep 26, 2023

chore: devnet redeployment with upgradable contracts 🚀

acb94e9
Select commit
Loading
Failed to load commit list.
Merged

Feat(contracts)/upgradability #1214

chore: devnet redeployment with upgradable contracts 🚀
acb94e9
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / Mend Security Check failed Sep 26, 2023 in 4m 23s

Security Report

The Security Check found 5 vulnerabilities.

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2023-26115

Dependency Hierarchy:

-> @kleros/kleros-v2-web-0.2.0.tgz (Root Library)

   -> react-scripts-5.0.1.tgz

     -> jest-27.5.1.tgz

       -> core-27.5.1.tgz

         -> jest-config-27.5.1.tgz

           -> jest-environment-jsdom-27.5.1.tgz

             -> jsdom-16.7.0.tgz

               -> escodegen-2.0.0.tgz

                 -> optionator-0.8.3.tgz

                   -> ❌ word-wrap-1.2.3.tgz (Vulnerable Library)

High 7.5 word-wrap-1.2.3.tgz Upgrade to version: word-wrap - 1.2.4 #1185
CVE-2022-25883

Dependency Hierarchy:

-> @kleros/kleros-v2-eslint-config-0.0.0.tgz (Root Library)

   -> eslint-plugin-node-11.1.0.tgz

     -> ❌ semver-6.3.0.tgz (Vulnerable Library)

High 7.5 semver-6.3.0.tgz Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 #985
CVE-2022-25883

Dependency Hierarchy:

-> @kleros/kleros-v2-web-0.2.0.tgz (Root Library)

   -> client-0.0.5.tgz

     -> ipfs-car-0.7.0.tgz

       -> meow-9.0.0.tgz

         -> read-pkg-up-7.0.1.tgz

           -> read-pkg-5.2.0.tgz

             -> normalize-package-data-2.5.0.tgz

               -> ❌ semver-5.7.1.tgz (Vulnerable Library)

High 7.5 semver-5.7.1.tgz Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 #1185
CVE-2021-3803

Dependency Hierarchy:

-> @kleros/kleros-v2-web-0.2.0.tgz (Root Library)

   -> react-scripts-5.0.1.tgz

     -> webpack-5.5.0.tgz

       -> plugin-svgo-5.5.0.tgz

         -> svgo-1.3.2.tgz

           -> css-select-2.1.0.tgz

             -> ❌ nth-check-1.0.2.tgz (Vulnerable Library)

High 7.5 nth-check-1.0.2.tgz Upgrade to version: nth-check - v2.0.1 #1185
CVE-2023-26144

Dependency Hierarchy:

-> @kleros/kleros-v2-web-0.2.0.tgz (Root Library)

   -> ❌ graphql-16.7.1.tgz (Vulnerable Library)

Medium 5.3 graphql-16.7.1.tgz Upgrade to version: graphql - 16.8.1 #1185

Total libraries scanned: 1954
Scan token: d445321ff9934cfca7e43598a60f3f7f