Skip to content

Advisory with NPM package elliptic (all versions) #1157

@JaimeValdemoros

Description

@JaimeValdemoros

I have an NPM repo running @stackframe/react version 2.8.64, matching the latest at package.json.

npm audit report shows the following:

# npm audit report

elliptic  *
Elliptic Uses a Cryptographic Primitive with a Risky Implementation - https://github.com/advisories/GHSA-848j-6mx2-7j84
No fix available
node_modules/elliptic
  @stackframe/stack-shared  >=2.5.31
  Depends on vulnerable versions of elliptic
  node_modules/@stackframe/react/node_modules/@stackframe/stack-shared
    @stackframe/react  *
    Depends on vulnerable versions of @stackframe/stack-shared
    Depends on vulnerable versions of @stackframe/stack-ui
    node_modules/@stackframe/react
    @stackframe/stack-ui  >=2.5.31
    Depends on vulnerable versions of @stackframe/stack-shared
    node_modules/@stackframe/react/node_modules/@stackframe/stack-ui

4 low severity vulnerabilities

To address issues that do not require attention, run:
  npm audit fix

Some issues need review, and may require choosing
a different dependency.

The advisory being referred to is this one, raised last month: GHSA-848j-6mx2-7j84

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions