Skip to content

Conversation

@ovitrif
Copy link
Contributor

@ovitrif ovitrif commented Jul 28, 2025

Description

This PR force-updates tiny-secp256k1 -- via dependency resolutions -- to the next immediate version supposed to patch the 2 dependabot vulnerability alerts listed below.

Linked Issues/Tasks

Dependabot alerts:

Type of change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Refactoring (improving code without creating new functionality)

Tests

  • Existing suite should pass

Screenshot / Video

n/a

QA Notes

If automated tests pass we are ok.

@ovitrif ovitrif requested review from Jasonvdb and pwltr July 28, 2025 09:34
@socket-security
Copy link

socket-security bot commented Jul 28, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​strip-final-newline@​3.0.01001006676100
Addednpm/​onetime@​6.0.01001009876100
Addednpm/​npm-run-path@​5.3.010010010077100
Addednpm/​conventional-changelog-angular@​7.0.010010010082100
Addednpm/​conventional-commits-parser@​5.0.010010010085100

View full report

@ovitrif ovitrif force-pushed the chore/dep-update branch from 814ea88 to c01d99e Compare July 28, 2025 11:38
@pwltr pwltr merged commit 1f8c588 into master Jul 28, 2025
7 checks passed
@pwltr pwltr deleted the chore/dep-update branch July 28, 2025 13:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants