Fix dependency vulnerability by upgrading xmlhttprequest-ssl via yarn.lock#10990
Fix dependency vulnerability by upgrading xmlhttprequest-ssl via yarn.lock#10990
Conversation
|
CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes. |
|
Further comments on this fix:
Of those, only 4 appear to be potentially functional: I think all of these will be non-breaking for engine-io.client:
Even if my read of all of those is incorrect, I am 99% sure that 3box's use of ipfs does not rely on libp2p-webrtc-star. 3box creates an ipfs instance, which in turn instantiates libp2p-webrtc-star. However, 3box only uses the following properties/methods on these ipfs instances: And none of these rely on libp2p-webrtc-star It also seems safe for eth-trezor-keyring, which only relies on the |
Builds ready [1850b7b]
Page Load Metrics (629 ± 60 ms)
|

This fixes these code vulnerabilities: