Skip to content

npm audit alert being triggered - alchemy-sdk tied to 3-year-old @ethersproject/providers 5.7.2 - with ws 7.x #468

@respectabiggle

Description

@respectabiggle

Sorry if this has been addressed or if I'm missing something obvious.

[REQUIRED] Environment

Win10

  • Browser version: none
  • Alchemy SDK version: 3.4.7

[REQUIRED] Describe the problem

npm audit shows

ws 7.0.0 - 7.5.9
Severity: high
ws affected by a DoS when handling a request with many HTTP headers - GHSA-3h5v-q93c-6h6q
No fix available
node_modules/@ethersproject/providers/node_modules/ws
@ethersproject/providers <=5.7.2
Depends on vulnerable versions of ws
node_modules/@ethersproject/providers
alchemy-sdk *
Depends on vulnerable versions of @ethersproject/providers
node_modules/alchemy-sdk

How to reproduce:

npm audit

Relevant code or sample repro:

all my Alchemy code works fine (thanks)

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions