We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Improper Verification of Cryptographic Signature has High security severity score in snyk reports 8.7 Affecting elliptic package, versions <6.6.0
https://security.snyk.io/vuln/SNYK-JS-ELLIPTIC-8187303 Need to upgrade elliptic package to latest version 6.6.1
The text was updated successfully, but these errors were encountered:
Yes, flagged by AWS inspector also in my case Elliptic has fixed this - indutny/elliptic#325
Could we upgrade the package and release new version
Sorry, something went wrong.
jwk-to-pem's constraint on elliptic already matched the updated version.
However, I've release 2.0.7 should that help your teams with your scanners.
Consider moving your usage away from jwk-to-pem to modern Node.js features: #187 (comment)
No branches or pull requests
Improper Verification of Cryptographic Signature has High security severity score in snyk reports 8.7
Affecting elliptic package, versions <6.6.0
https://security.snyk.io/vuln/SNYK-JS-ELLIPTIC-8187303
Need to upgrade elliptic package to latest version 6.6.1
The text was updated successfully, but these errors were encountered: