Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): fabric connector upgrade bl #499

Conversation

petermetz
Copy link
Contributor

@petermetz petermetz commented Jan 15, 2021

Fixes #498

commit 5431c4708e842fb4c8384882bd4d5e02f7bef045
Author: Peter Somogyvari <peter.somogyvari@accenture.com>
Date:   Fri Jan 15 11:44:33 2021 -0800

    chore(deps): specify explicit bl version 1.2.3 in fabric plugin
    
    This is necessary so that we can resolve the issue of us
    being susceptible to this CVE:
    
    https://github.com/advisories/GHSA-pp7h-53gx-mx7r
    
    Fixes #498
    
    Signed-off-by: Peter Somogyvari <peter.somogyvari@accenture.com>

Depends on #506

@petermetz petermetz added Fabric Security Related to existing or potential security vulnerabilities labels Jan 15, 2021
@petermetz petermetz added this to the v0.4.0 milestone Jan 15, 2021
@petermetz petermetz changed the title chore/deps/fabric connector upgrade bl chore(deps): fabric connector upgrade bl Jan 15, 2021
@petermetz petermetz enabled auto-merge (rebase) January 15, 2021 19:46
@petermetz petermetz added the help wanted Extra attention is needed label Jan 15, 2021
@petermetz petermetz force-pushed the chore/deps/fabric-connector-upgrade-bl-498 branch 2 times, most recently from edaea2a to 7ac5df4 Compare January 19, 2021 19:52
Copy link
Contributor

@jonathan-m-hamilton jonathan-m-hamilton left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

This is necessary so that we can resolve the issue of us
being susceptible to this CVE:

GHSA-pp7h-53gx-mx7r

Fixes hyperledger-cacti#498

Signed-off-by: Peter Somogyvari <peter.somogyvari@accenture.com>
@petermetz petermetz force-pushed the chore/deps/fabric-connector-upgrade-bl-498 branch from 00dc777 to 14c8c5e Compare January 26, 2021 00:30
@github-actions
Copy link

🎉 Great news! Looks like all the dependencies have been resolved:

💡 To add or remove a dependency please update this issue/PR description.

Brought to you by Dependent Issues (:robot: ). Happy coding!

@petermetz petermetz merged commit b13b213 into hyperledger-cacti:main Jan 26, 2021
@petermetz petermetz deleted the chore/deps/fabric-connector-upgrade-bl-498 branch January 26, 2021 17:34
sandeepnRES added a commit to sandeepnRES/cacti that referenced this pull request Apr 3, 2023
    - Prototype Pollution in immer hyperledger-cacti#434 hyperledger-cacti#435
    - Overflow in prost-types hyperledger-cacti#423
    - Dependabot alerts hyperledger-cacti#499
    - Dependabot alerts hyperledger-cacti#570

Signed-off-by: Sandeep Nishad <sandeep.nishad1@ibm.com>
sandeepnRES added a commit to sandeepnRES/cacti that referenced this pull request Apr 3, 2023
    - Prototype Pollution in immer hyperledger-cacti#434 hyperledger-cacti#435
    - Overflow in prost-types hyperledger-cacti#423
    - Dependabot alerts hyperledger-cacti#499
    - Dependabot alerts hyperledger-cacti#570

Signed-off-by: Sandeep Nishad <sandeep.nishad1@ibm.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Fabric help wanted Extra attention is needed Security Related to existing or potential security vulnerabilities
Projects
None yet
Development

Successfully merging this pull request may close these issues.

chore(deps): fabric connector upgrade bl
3 participants