Skip to content

Fix: bump valibot#99

Merged
junderw merged 2 commits intobitcoinjs:masterfrom
landabaso:fix/bump-valibot
Feb 19, 2026
Merged

Fix: bump valibot#99
junderw merged 2 commits intobitcoinjs:masterfrom
landabaso:fix/bump-valibot

Conversation

@landabaso
Copy link
Member

Bumps valibot to ^1.2.0 to fix a high severity ReDoS vulnerability in EMOJI_REGEX.
Also updates npm version to 5.0.1.

This is the same issue addressed in bitcoinjs/ecpair#34 and bitcoinjs/bitcoinjs-lib#2308.

I can also handle the release @junderw, if that's ok.

@junderw junderw merged commit c8042b8 into bitcoinjs:master Feb 19, 2026
6 checks passed
@junderw
Copy link
Member

junderw commented Feb 19, 2026

Thanks. If you could release I'd appreciate it!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants