vechain/thor-devkit.js

Use of a Broken or Risky Cryptographic Algorithm

ehamery opened this issue · 6 comments

The elliptic package is reported as not safe by npm audit, see the advisory. It needs to be updated to a version >=6.5.4.

The elliptic package is reported as not safe by npm audit, see the advisory. It needs to be update to a version >=6.5.4.

thanks. I'll check it soon.

just published v2.0.2 fixes the problem.

Thanks, then could you update connex as well?

I created a PR to fix the other vulnerabilities.

Thanks, then could you update connex as well?

Connex was updated.

This issue is fixed, so I am closing it, but there are other vulnerabilities that are fixed by this PR.