Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned #87

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 3, 2021

Mend Renovate

This PR contains the following updates:

Package Change
elliptic 6.5.1 -> 6.5.4

GitHub Vulnerability Alerts

CVE-2020-13822

The Elliptic package before version 6.5.3 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact if an application relied on a single canonical signature.

CVE-2020-28498

The npm package elliptic before version 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.


Configuration

📅 Schedule: Branch creation - "after 7pm every weekday,every weekend,before 8am every weekday" in timezone Australia/Melbourne, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.3 [SECURITY] [patch] Update dependency elliptic to 6.5.4 [SECURITY] Mar 9, 2021
@renovate renovate bot force-pushed the renovate/npm-elliptic-vulnerability branch from 218cd1b to aafdcb5 Compare March 7, 2022 11:41
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned Mar 24, 2023
@renovate
Copy link
Contributor Author

renovate bot commented Mar 24, 2023

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned [patch] Update dependency elliptic to 6.5.4 [SECURITY] Mar 30, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned Mar 30, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned [patch] Update dependency elliptic to 6.5.4 [SECURITY] Mar 31, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned Mar 31, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned [patch] Update dependency elliptic to 6.5.4 [SECURITY] Mar 31, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned Mar 31, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned [patch] Update dependency elliptic to 6.5.4 [SECURITY] Mar 31, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned Mar 31, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned [patch] Update dependency elliptic to 6.5.4 [SECURITY] Mar 31, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned Apr 3, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned - autoclosed Apr 6, 2023
@renovate renovate bot closed this Apr 6, 2023
@renovate renovate bot deleted the renovate/npm-elliptic-vulnerability branch April 6, 2023 01:16
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned - autoclosed [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned Apr 6, 2023
@renovate renovate bot reopened this Apr 6, 2023
@renovate renovate bot restored the renovate/npm-elliptic-vulnerability branch April 6, 2023 04:41
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned [patch] Update dependency elliptic to 6.5.4 [SECURITY] Apr 6, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned Apr 17, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned [patch] Update dependency elliptic to 6.5.4 [SECURITY] May 17, 2023
@renovate renovate bot changed the title [patch] Update dependency elliptic to 6.5.4 [SECURITY] [patch] Update dependency elliptic to 6.5.4 [SECURITY] - abandoned May 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant