Consensys / Consensys/abi-decoder
Nose Security warning (hoek)
- Dominant language
- JavaScript
- Stars
- 641
- Forks
- 215
- PR merge metrics
- No merged PRs in 30d
Description
https://nodesecurity.io/orgs/metamask/projects/6680bc33-6e65-4db7-a943-2aef82f2a881/3458
```
Vulnerable: <= 4.2.0 || >= 5.0.0 < 5.0.3 - Patched: > 4.2.0 < 5.0.0 || >= 5.0.3 - Path: abi-decoder@1.0.9 > webpack@2.7.0 > watchpack@1.5.0 > chokidar@2.0.2 > fsevents@1.1.3 > node-pre-gyp@0.6.39 > hawk@3.1.3 > hoek@2.16.3
```
Likely fixed by bumping webpack
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the dependency path shown in the issue, especially webpack@2.7.0 and its transitive hoek@2.16.3 dependency. Verify the available webpack upgrade and rerun the project's dependency or security checks; done means the reported vulnerable hoek range is no longer present.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, webpack
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100