We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade the CosmosSDK version to 0.50.5 or newer and ensure that dependabot reports dependency security issues.
0.50.5
dependabot
CosmosSDK had a security issue in versions prior to 0.50.5 and dependabot in the poktroll repository did not catch it.
poktroll
This is the notification received by shannon-sdk's dependabot [1]:
shannon-sdk
https://github.com/pokt-network/shannon-sdk/security/dependabot/3
Creator: [@red-0ne]
The text was updated successfully, but these errors were encountered:
Sorry, something went wrong.
okdas
No branches or pull requests
Objective
Upgrade the CosmosSDK version to
0.50.5
or newer and ensure thatdependabot
reports dependency security issues.Origin Document
CosmosSDK had a security issue in versions prior to
0.50.5
anddependabot
in thepoktroll
repository did not catch it.This is the notification received by
![image](https://private-user-images.githubusercontent.com/231488/336967857-214de20e-edc8-4918-9c74-4ceaeb0c0d20.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk2MDU0MDEsIm5iZiI6MTczOTYwNTEwMSwicGF0aCI6Ii8yMzE0ODgvMzM2OTY3ODU3LTIxNGRlMjBlLWVkYzgtNDkxOC05Yzc0LTRjZWFlYjBjMGQyMC5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjUwMjE1JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI1MDIxNVQwNzM4MjFaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT1jY2IyMWJhZTYwODA4OGU1NTA5NmViZDQ0MmRjY2VjMzg5N2Q4Njk3M2Y0NmZmNTJkOTU4ZTBkMzBkYTljZTQxJlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCJ9.UyQKS8XOxrBFPYHEPmfslfyv2KWTMYMoV2TeeY1AQMM)
shannon-sdk
'sdependabot
[1]:https://github.com/pokt-network/shannon-sdk/security/dependabot/3
Goals
dependabot
in thepoktroll
repository catches future security issues.Deliverables
poktroll
's CosmosSDK (github.com/cosmos/cosmos-sdk) dependency to version0.50.5
or newer.poktroll
repository to cach future dependency vulnerabilities.Creator: [@red-0ne]
The text was updated successfully, but these errors were encountered: