Skip to content

Comments

update transient dependencies#13

Merged
vtiwari-story merged 2 commits intomainfrom
transient-dependency
Sep 25, 2025
Merged

update transient dependencies#13
vtiwari-story merged 2 commits intomainfrom
transient-dependency

Conversation

@vtiwari-story
Copy link
Collaborator

Description

Updating transient dependencies.

Notes

hardhat-deploy@0.11.45 was using an older version of axios. So updated hardhat-deploy to the latest version.

@wiz-837b06c6da
Copy link

wiz-837b06c6da bot commented Sep 25, 2025

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities -
Data Finding Sensitive Data -
Total -

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

jsbn "~0.1.0"
safer-buffer "^2.1.0"

elliptic@6.5.4:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Critical Vulnerability Finding

More Details

Vulnerabilities [elliptic:6.5.4]

Name Severity Source Fixed version CVSS score CVSS exploitability score Has public exploit Has CISA KEV exploit
CVE-2024-42459 Low GHSA-f7q4-pwc6-w24p 6.5.7 5.3 3.9 false false
CVE-2024-42460 Low GHSA-977x-g7h5-7qgw 6.5.7 5.3 3.9 false false
CVE-2024-42461 Low GHSA-49q7-c7j4-3p7m 6.5.7 9.1 3.9 false false
CVE-2024-48948 Low GHSA-fc9h-whq2-v747 6.6.0 4.8 2.2 false false
CVE-2024-48949 Low GHSA-434g-2637-qmqr 6.5.6 9.1 3.9 false false
GHSA-vjh7-7g9h-fjfh Critical GHSA-vjh7-7g9h-fjfh 6.6.1 9.0 - false false

To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason

If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we need to address this?

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

#wiz_ignore transient dependency

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The finding has been successfully ignored for these checks.

If you'd like to ignore this finding in all future scans, you can add a matching exception in the .wiz file.
Learn more

@vtiwari-story vtiwari-story merged commit 982ffe0 into main Sep 25, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants