Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ethjs is discontinued and contains security vulnerabilities #224

Closed
nikolockenvitz opened this issue Aug 21, 2020 · 2 comments
Closed

ethjs is discontinued and contains security vulnerabilities #224

nikolockenvitz opened this issue Aug 21, 2020 · 2 comments
Assignees
Labels
dependencies Refers to an update of a dependency file wontfix This will not be worked on

Comments

@nikolockenvitz
Copy link

ethjs libraries are used in this repo but they are discontinued (see this and this comment).

Even if PRs are still accepted packages would also need to be relased to use these updates. As you can see in this PR they still depend on vulnerable versions of other packages and as they specified the version exactly, it's hard to update to the fixed version.

IMO they should be replaced. Is that already planned or are you working on that already / how is the progress/timeline?

This also affects other repos, e.g. ethr-did

@mirceanis
Copy link
Member

Thank you for spotting this.
We are aware of the deprecation and had already started moving to the ethers.js backbone for ETH operations.
The update will have to happen first in ethr-did since that is the principal dependent, and a small correction needs to be done in DAF after that to adapt to the new API.

@mirceanis mirceanis added the dependencies Refers to an update of a dependency file label Aug 26, 2020
@stale
Copy link

stale bot commented Dec 19, 2020

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the wontfix This will not be worked on label Dec 19, 2020
@stale stale bot closed this as completed Dec 26, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Refers to an update of a dependency file wontfix This will not be worked on
Projects
None yet
Development

No branches or pull requests

2 participants