Skip to content

Commit b0caca5

Browse files
fix(deps): surgical yarn.lock pin for get-func-name CVE-2023-43646
Pin get-func-name@^2.0.0 to 2.0.2 in solidity/ecdsa and solidity/random-beacon yarn.lock files using the resolved URL and integrity hash from the yarn registry. The npm `overrides` field in package.json is ignored by Yarn Classic (1.22.x); a direct yarn.lock pin is required instead. Note: token-stakedrop/merkle-distributor yarn.lock contains the same pattern but is a git submodule of keep-network/merkle-distributor where push access is required. That fix needs a separate PR.
1 parent 58f8656 commit b0caca5

2 files changed

Lines changed: 6 additions & 6 deletions

File tree

solidity/ecdsa/yarn.lock

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6394,9 +6394,9 @@ get-caller-file@^2.0.1, get-caller-file@^2.0.5:
63946394
integrity sha512-DyFP3BM/3YHTQOCUL/w0OZHR0lpKeGrxotcHWcqNEdnltqFwXVfhEBQ94eIo34AfQpo0rGki4cyIiftY06h2Fg==
63956395

63966396
get-func-name@^2.0.0:
6397-
version "2.0.0"
6398-
resolved "https://registry.npmjs.org/get-func-name/-/get-func-name-2.0.0.tgz"
6399-
integrity sha1-6td0q+5y4gQJQzoGY2YCPdaIekE=
6397+
version "2.0.2"
6398+
resolved "https://registry.yarnpkg.com/get-func-name/-/get-func-name-2.0.2.tgz#0d7cf20cd13fda808669ffa88f4ffc7a3943fc41"
6399+
integrity sha512-8vXOvuE167CtIc3OyItco7N/dpRtBbYOsPsXCz7X/PMnlGjYjSGuZJgM1Y7mmew7BKf9BqvLX2tnOVy1BBUsxQ==
64006400

64016401
get-intrinsic@^1.2.4, get-intrinsic@^1.2.5, get-intrinsic@^1.2.6, get-intrinsic@^1.2.7, get-intrinsic@^1.3.0:
64026402
version "1.3.0"

solidity/random-beacon/yarn.lock

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5789,9 +5789,9 @@ get-caller-file@^2.0.1, get-caller-file@^2.0.5:
57895789
integrity sha512-DyFP3BM/3YHTQOCUL/w0OZHR0lpKeGrxotcHWcqNEdnltqFwXVfhEBQ94eIo34AfQpo0rGki4cyIiftY06h2Fg==
57905790

57915791
get-func-name@^2.0.0:
5792-
version "2.0.0"
5793-
resolved "https://registry.yarnpkg.com/get-func-name/-/get-func-name-2.0.0.tgz#ead774abee72e20409433a066366023dd6887a41"
5794-
integrity sha1-6td0q+5y4gQJQzoGY2YCPdaIekE=
5792+
version "2.0.2"
5793+
resolved "https://registry.yarnpkg.com/get-func-name/-/get-func-name-2.0.2.tgz#0d7cf20cd13fda808669ffa88f4ffc7a3943fc41"
5794+
integrity sha512-8vXOvuE167CtIc3OyItco7N/dpRtBbYOsPsXCz7X/PMnlGjYjSGuZJgM1Y7mmew7BKf9BqvLX2tnOVy1BBUsxQ==
57955795

57965796
get-intrinsic@^1.0.2:
57975797
version "1.1.3"

0 commit comments

Comments
 (0)