From 7ecbdf8b20560938b3ddf5af5f9f16bc2ccc2933 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 4 Jan 2026 10:19:40 +0000 Subject: [PATCH 1/3] fix: package.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-QS-14724253 --- package.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index 95efeb9059..1d40a36628 100644 --- a/package.json +++ b/package.json @@ -116,7 +116,7 @@ "@reduxjs/toolkit": "^1.8.0", "@rjsf/core": "^4.2.2", "@safe-global/api-kit": "^1.3.0", - "@safe-global/protocol-kit": "^1.2.0", + "@safe-global/protocol-kit": "^4.0.0", "@safe-global/safe-apps-sdk": "^9.1.0", "@safe-global/safe-core-sdk-types": "^2.2.0", "@safe-global/safe-ethers-lib": "^1.9.4", @@ -201,7 +201,7 @@ "polished": "^4.0.5", "polyfill-object.fromentries": "^1.0.1", "popper-max-size-modifier": "^0.2.0", - "qs": "^6.12.1", + "qs": "^6.14.1", "quick-lru": "^7.0.0", "react": "19.1.2", "react-appzi": "^1.0.4", From f299bcb504c2ab2f0fa569bf1933f1e1ce47ad84 Mon Sep 17 00:00:00 2001 From: Daniel Constantin Date: Mon, 5 Jan 2026 18:15:39 +0200 Subject: [PATCH 2/3] chore: revert @safe-global/protocol-kit upgrade --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 1d40a36628..1b79e9c02a 100644 --- a/package.json +++ b/package.json @@ -116,7 +116,7 @@ "@reduxjs/toolkit": "^1.8.0", "@rjsf/core": "^4.2.2", "@safe-global/api-kit": "^1.3.0", - "@safe-global/protocol-kit": "^4.0.0", + "@safe-global/protocol-kit": "^1.2.0", "@safe-global/safe-apps-sdk": "^9.1.0", "@safe-global/safe-core-sdk-types": "^2.2.0", "@safe-global/safe-ethers-lib": "^1.9.4", From 8fb0637e95f956b4cfc083f739735af4e3abb53a Mon Sep 17 00:00:00 2001 From: Daniel Constantin Date: Mon, 5 Jan 2026 18:16:08 +0200 Subject: [PATCH 3/3] chore: update yarn.lock --- yarn.lock | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/yarn.lock b/yarn.lock index c08580b99b..a6ee7e89a8 100644 --- a/yarn.lock +++ b/yarn.lock @@ -26935,12 +26935,12 @@ qs@6.14.0, qs@^6.12.3: dependencies: side-channel "^1.1.0" -qs@^6.12.1: - version "6.12.1" - resolved "https://registry.yarnpkg.com/qs/-/qs-6.12.1.tgz#39422111ca7cbdb70425541cba20c7d7b216599a" - integrity sha512-zWmv4RSuB9r2mYQw3zxQuHWeU+42aKi1wWig/j4ele4ygELZ7PEO6MM7rim9oAQH2A5MWfsAVf/jPvTPgCbvUQ== +qs@^6.14.1: + version "6.14.1" + resolved "https://registry.yarnpkg.com/qs/-/qs-6.14.1.tgz#a41d85b9d3902f31d27861790506294881871159" + integrity sha512-4EK3+xJl8Ts67nLYNwqw/dsFVnCf+qR7RgXSK9jEEm9unao3njwMDdmsdvoKBKHzxd7tCYz5e5M+SnMjdtXGQQ== dependencies: - side-channel "^1.0.6" + side-channel "^1.1.0" qs@^6.4.0, qs@^6.5.1: version "6.11.2"