Skip to content
This repository was archived by the owner on Apr 25, 2024. It is now read-only.

Conversation

@chloe-tan
Copy link

@chloe-tan chloe-tan commented Apr 22, 2024

Issue

Current v3-staker version (1.0.0) depends on a vulnerable version of @openzeppelin/contracts. Sample dependabot alerts:

image

Changelog

  1. Update @uniswap/v3-staker dependency to v1.0.2

Linked issues

#195

@chloe-tan chloe-tan changed the title chore: update v3-staker to v1.0.2 chore: update @uniswap/v3-staker dependency to v1.0.2 Apr 22, 2024
@socket-security
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@uniswap/[email protected] None +1 1.45 MB noahwz

🚮 Removed packages: npm/@uniswap/[email protected]

View full report↗︎

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant