Consensys / Consensys/abi-decoder

Nose Security warning (hoek)

Open
#12 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
641
Forks
215
PR merge metrics
No merged PRs in 30d

Description

https://nodesecurity.io/orgs/metamask/projects/6680bc33-6e65-4db7-a943-2aef82f2a881/3458
```
Vulnerable: <= 4.2.0 || >= 5.0.0 < 5.0.3 - Patched: > 4.2.0 < 5.0.0 || >= 5.0.3 - Path: abi-decoder@1.0.9 > webpack@2.7.0 > watchpack@1.5.0 > chokidar@2.0.2 > fsevents@1.1.3 > node-pre-gyp@0.6.39 > hawk@3.1.3 > hoek@2.16.3
```

Likely fixed by bumping webpack

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the dependency path shown in the issue, especially webpack@2.7.0 and its transitive hoek@2.16.3 dependency. Verify the available webpack upgrade and rerun the project's dependency or security checks; done means the reported vulnerable hoek range is no longer present.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, webpack
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.