From 8978768890b945d36d78eedb0019d877ca327dca Mon Sep 17 00:00:00 2001 From: Pawel Zelawski Date: Thu, 10 Apr 2025 19:08:03 +0200 Subject: fix(deps): override elliptic and lodash to fix vulnerabilities - Add npm overrides for elliptic (^6.6.1) and lodash (^4.17.21) in package.json. - This resolves multiple security vulnerabilities reported by GitHub Dependabot in these transitive dependencies, inherited via digibyte-message. - Updates package-lock.json to reflect the overridden versions. --- package.json | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'package.json') diff --git a/package.json b/package.json index 79849c5..8468c97 100644 --- a/package.json +++ b/package.json @@ -72,5 +72,9 @@ }, "dependencies": { "digibyte-message": "github:digicontributer/bitcore-message#9d9c8ad30158db25f683e2dee746a14a9d7ec8a0" + }, + "overrides": { + "elliptic": "^6.6.1", + "lodash": "^4.17.21" } } -- cgit v1.2.3