Skip to content

Advisory with NPM package elliptic (all versions) #1157

@JaimeValdemoros

Description

@JaimeValdemoros

I have an NPM repo running @stackframe/react version 2.8.64, matching the latest at package.json.

npm audit report shows the following:

# npm audit report

elliptic  *
Elliptic Uses a Cryptographic Primitive with a Risky Implementation - https://github.com/advisories/GHSA-848j-6mx2-7j84
No fix available
node_modules/elliptic
  @stackframe/stack-shared  >=2.5.31
  Depends on vulnerable versions of elliptic
  node_modules/@stackframe/react/node_modules/@stackframe/stack-shared
    @stackframe/react  *
    Depends on vulnerable versions of @stackframe/stack-shared
    Depends on vulnerable versions of @stackframe/stack-ui
    node_modules/@stackframe/react
    @stackframe/stack-ui  >=2.5.31
    Depends on vulnerable versions of @stackframe/stack-shared
    node_modules/@stackframe/react/node_modules/@stackframe/stack-ui

4 low severity vulnerabilities

To address issues that do not require attention, run:
  npm audit fix

Some issues need review, and may require choosing
a different dependency.

The advisory being referred to is this one, raised last month: GHSA-848j-6mx2-7j84

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions