Skip to content

fix(security): Remove bitcoin-elliptic & Use Patched elliptic for Security Improvements#262

Open
emadgit wants to merge 1 commit intomoneybutton:masterfrom
emadgit:master
Open

fix(security): Remove bitcoin-elliptic & Use Patched elliptic for Security Improvements#262
emadgit wants to merge 1 commit intomoneybutton:masterfrom
emadgit:master

Conversation

@emadgit
Copy link

@emadgit emadgit commented Feb 21, 2025

There was a critical vulnerability in Elliptic lib, which used by one of the dependencies of bsv called bitcoin-elliptic, which seems to be an old outdated and unmaintained package ( bitcoin-elliptic Repo ).

This PR removes the unmaintained bitcoin-elliptic library which is using a very old version of elliptic, from bsv and replaces its usage with the latest version of elliptic (^6.6.1), which includes necessary security patches.

Changes:

  • Removed bitcoin-elliptic as a dependency.
  • Add the elliptic (^6.6.1) which includes necessary security patches
  • Updated bsv to directly use elliptic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant