Skip to content

Conversation

@emadgit
Copy link

@emadgit emadgit commented Feb 21, 2025

There was a critical vulnerability in Elliptic lib, which used by one of the dependencies of bsv called bitcoin-elliptic, which seems to be an old outdated and unmaintained package ( bitcoin-elliptic Repo ).

This PR removes the unmaintained bitcoin-elliptic library which is using a very old version of elliptic, from bsv and replaces its usage with the latest version of elliptic (^6.6.1), which includes necessary security patches.

Changes:

  • Removed bitcoin-elliptic as a dependency.
  • Add the elliptic (^6.6.1) which includes necessary security patches
  • Updated bsv to directly use elliptic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant