Dependabot: leave the uuid alert (GHSA-w5hq-g745-h8pq) open until MetaMask SDK bumps uuid
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Newbie friendliness
- 64/100
- Issue type
- Documentation
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- node.js, typescript
- Domain
- security
Research direction
Review the GHSA-w5hq-g745-h8pq alert and the dependency path through @metamask/sdk and @metamask/utils first; no repository file or test is named. Done means keeping the alert open until a MetaMask SDK update brings uuid to 11.1.1, then confirming it clears; if upstream remains unchanged, revisit the documented rationale.
Written by the indexing model from the issue text.
Description
One Dependabot alert is left open on purpose after #64 cleared the other twelve, filing this so the reasoning isn't lost and nobody spends an afternoon re-deriving it.
The alert is GHSA-w5hq-g745-h8pq on uuid (8.3.2 and 9.0.1 in our tree). It's a missing bounds check in uuid's v3/v5/v6 functions when you hand them a buf to write into. We pull uuid transitively through the MetaMask SDK (@metamask/sdk, @metamask/utils), which only uses v4, so the vulnerable path isn't reachable from anything we ship.
The only patched version is 11.1.1. That's a major jump from 8/9, and forcing it breaks the CJS require chain the MetaMask packages rely on, so it's real breakage for effectively zero exposure. Not worth it.
Leaving it open rather than dismissing: it should clear on its own once a MetaMask SDK update bumps uuid to 11, and an open alert is a fine reminder to check. If it's still here in a few months with no upstream movement, revisit, either dismiss with this rationale or pin uuid 11 once the MetaMask chain supports it.
- Dominant language
- TypeScript
- Stars
- 1
- Forks
- 2
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from NethermindEth/aztec-gov
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
NethermindEth/aztec-gov#40 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 52/100
NethermindEth/aztec-gov#25 ·
All issues in NethermindEth/aztec-gov
Similar issues
-
calcite-components needs triage refactor
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Esri/calcite-design-system#15203 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 91/100
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Difficulty 1/5 Under an hour Newbie friendliness 95/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Automattic/studio#4908 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100