[Snyk] Security upgrade wagmi from 2.14.15 to 3.0.0 - #29
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
Summary of ChangesHello @Dargon789, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request aims to enhance the project's security posture by upgrading the 'wagmi' dependency to its latest major version, '3.0.0'. This critical update directly addresses a known vulnerability related to cryptographic signature verification. Reviewers should pay close attention to potential breaking changes introduced by the major version bump and ensure the manual update of the 'pnpm-lock.yaml' file is completed. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request, automatically generated by Snyk, proposes upgrading wagmi from version 2 to version 3 to fix a security vulnerability. While addressing security is crucial, this is a major version upgrade with significant breaking changes that will likely break the application due to API incompatibilities and conflicts with other dependencies like @coinbase/onchainkit which rely on wagmi v2. The PR also notes a failure to update the pnpm-lock.yaml file. I have left a comment recommending an alternative, safer approach: using pnpm overrides to patch the transitive dependency vulnerability directly, without the risks of a major version bump. This will require manual intervention but is a much more stable solution.
|
Deployment failed with the following error: Learn More: https://vercel.com/dargon789-forge?upgradeToPro=build-rate-limit |
…rabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-ELLIPTIC-8187303
38ed8f4 to
3319f76
Compare
Snyk has created this PR to fix 1 vulnerabilities in the pnpm dependencies of this project.
Snyk changed the following file(s):
packages/miniapp-manifest-generator/package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-ELLIPTIC-8187303
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.