Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Aug 15, 2024

This PR contains the following updates:

Package Change Age Confidence
elliptic 6.5.4 -> 6.5.7 age confidence

GitHub Vulnerability Alerts

CVE-2024-42459

In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.

CVE-2024-42461

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

CVE-2024-42460

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.


Release Notes

indutny/elliptic (elliptic)

v6.5.7

Compare Source

v6.5.6

Compare Source

v6.5.5

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-elliptic-vulnerability branch from 819ea55 to 61fede5 Compare October 24, 2024 14:32
@renovate renovate bot force-pushed the renovate/npm-elliptic-vulnerability branch from 61fede5 to c7a7164 Compare January 21, 2025 19:47
@renovate renovate bot force-pushed the renovate/npm-elliptic-vulnerability branch from c7a7164 to e337036 Compare May 19, 2025 16:51
@renovate renovate bot changed the title Update dependency elliptic to v6.5.7 [SECURITY] Update dependency elliptic to v6.6.1 [SECURITY] Aug 13, 2025
@renovate renovate bot force-pushed the renovate/npm-elliptic-vulnerability branch from e337036 to 65c3750 Compare August 17, 2025 01:14
@renovate renovate bot changed the title Update dependency elliptic to v6.6.1 [SECURITY] Update dependency elliptic to v6.5.7 [SECURITY] Oct 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants