Skip to content

Resolve Security Vulnerabilities - #122

Closed
ElliotWood13 wants to merge 2 commits into
ethena-labs:mainfrom
ElliotWood13:security-fixes
Closed

Resolve Security Vulnerabilities#122
ElliotWood13 wants to merge 2 commits into
ethena-labs:mainfrom
ElliotWood13:security-fixes

Conversation

@ElliotWood13

Copy link
Copy Markdown
Contributor
  • Upgrade form-data from 4.0.1 to 4.0.5 (CVE-2025-7783)
  • Upgrade base-x from 3.0.10/5.0.0 to 3.0.11/5.0.1 (homograph attack)
  • Replace bigint-buffer with bigint-buffer-fixed (buffer overflow)
  • Upgrade axios from 1.7.9/0.25.0 to 1.12.0+ (DoS and CSRF)
  • Upgrade @babel/runtime and @babel/core to 7.26.10+ (RegExp complexity)
  • Upgrade brace-expansion from 1.1.11 to 1.1.12 (ReDoS)
  • Upgrade js-yaml from 3.14.1 to 3.14.2 (prototype pollution)

- Upgrade form-data from 4.0.1 to 4.0.5 (CVE-2025-7783)
- Upgrade base-x from 3.0.10/5.0.0 to 3.0.11/5.0.1 (homograph attack)
- Replace bigint-buffer with bigint-buffer-fixed (buffer overflow)
- Upgrade axios from 1.7.9/0.25.0 to 1.12.0+ (DoS and CSRF)
- Upgrade @babel/runtime and @babel/core to 7.26.10+ (RegExp complexity)
- Upgrade brace-expansion from 1.1.11 to 1.1.12 (ReDoS)
- Upgrade js-yaml from 3.14.1 to 3.14.2 (prototype pollution)
@ElliotWood13
ElliotWood13 requested a review from a team as a code owner December 11, 2025 13:37
- Added constants for affluent integration start blocks in campaign.py.
- Updated error messages in affluent_integration.py and evaa_integration.py to clarify payload issues.
- Fixed string formatting in logging statements in strata_jrusde.py and strata_srusde.py.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant