Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: bump solana/web3.js version to 1.95.8 #1104

Closed
wants to merge 3 commits into from

Conversation

St0rmBr3w
Copy link
Contributor

@St0rmBr3w St0rmBr3w commented Dec 4, 2024

In response to a security incident that Anza has released details about, we are upgrading @solana/web3.js to version 1.95.8. Earlier today, a compromised publish-access account led to the release of malicious versions (1.95.6 and 1.95.7), which allowed attackers to steal private key material from applications that directly handle private keys.

While the affected versions have been unpublished, it is critical for all developers to upgrade to 1.95.8 to ensure security.

Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@layerzerolabs/[email protected] None +1 1.01 MB layerzero-bot

🚮 Removed packages: npm/@layerzerolabs/[email protected]

View full report↗︎

@DanL0
Copy link
Contributor

DanL0 commented Dec 4, 2024

Is this PR still relevant after #1102 was merged?

It doesn't seem to update any solana/web3.js package.

@ryandgoulding
Copy link
Contributor

@St0rmBr3w I don't think we need this anymore? Please feel free to re-open if I am wrong! Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants