Skip to content

CVE for dependency ecdsa #1108

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
trupus opened this issue May 28, 2025 · 1 comment
Open

CVE for dependency ecdsa #1108

trupus opened this issue May 28, 2025 · 1 comment

Comments

@trupus
Copy link

trupus commented May 28, 2025

Hi,

I noticed you switched from starkbank-ecdsa to ecdsa. There are currently 2 vulnerabilities for ecdsa CVE-2024-23342, PVE-2024-64396.

For now I'm just ignoring them in my CI pipeline, but what would be a better solution going forward?

Thanks

@manisha1997
Copy link
Contributor

Hello!
Thanks for raising the issue.
We are taking a look at alternatives.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants