Skip to content

Commit 46a366c

Browse files
authored
Merge branch 'develop' into rename-genesis-assertion-hash-method
2 parents a1759f9 + 9b7bd9b commit 46a366c

File tree

4 files changed

+33
-26
lines changed

4 files changed

+33
-26
lines changed

.github/workflows/contract-tests.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
- name: Install Foundry
2222
uses: foundry-rs/foundry-toolchain@v1
2323
with:
24-
version: stable
24+
version: v1.3.6
2525
cache: false
2626

2727
- name: Setup node/yarn
@@ -51,7 +51,7 @@ jobs:
5151
- name: Install Foundry
5252
uses: foundry-rs/foundry-toolchain@v1
5353
with:
54-
version: stable
54+
version: v1.3.6
5555
cache: false
5656

5757
- name: Setup nodejs
@@ -64,7 +64,7 @@ jobs:
6464
- name: Install Foundry
6565
uses: foundry-rs/foundry-toolchain@v1
6666
with:
67-
version: stable
67+
version: v1.3.6
6868
cache: false
6969

7070
- name: Check Contracts Format
@@ -134,7 +134,7 @@ jobs:
134134
- name: Install Foundry
135135
uses: foundry-rs/foundry-toolchain@v1
136136
with:
137-
version: stable
137+
version: v1.3.6
138138
cache: false
139139

140140
- uses: OffchainLabs/actions/run-nitro-test-node@main
@@ -267,7 +267,7 @@ jobs:
267267
# - name: Install Foundry
268268
# uses: foundry-rs/foundry-toolchain@v1
269269
# with:
270-
# version: stable
270+
# version: v1.3.6
271271
# cache: false
272272

273273
# - name: Setup node/yarn

audit-ci.jsonc

Lines changed: 6 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -16,21 +16,17 @@
1616
"GHSA-wprv-93r4-jj2p",
1717
// Open Zeppelin: Base64 encoding may read from potentially dirty memory
1818
"GHSA-9vx6-7xxf-x967",
19-
// semver vulnerable to Regular Expression Denial of Service
20-
"GHSA-c2qf-rxjj-qqgw",
2119
// Server-Side Request Forgery in axios
2220
"GHSA-8hc4-vh64-cxmj",
23-
// Regular Expression Denial of Service (ReDoS) in micromatch
24-
"GHSA-952p-6rrq-rcjv",
2521
// cookie accepts cookie name, path, and domain with out of bounds characters
2622
"GHSA-pxg6-pf52-xh8x",
27-
// Regular Expression Denial of Service (ReDoS) in cross-spawn
28-
"GHSA-3xgq-45jj-v275",
2923
// axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
3024
"GHSA-jr5f-v2jv-69x6",
31-
// Homograph attack allows Unicode lookalike characters to bypass validation
32-
"GHSA-xq7p-g2vc-g82p",
33-
// brace-expansion Regular Expression Denial of Service vulnerability
34-
"GHSA-v6h2-p8h4-qcjw"
25+
// tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
26+
"GHSA-52f5-9888-hmc6",
27+
// Axios is vulnerable to DoS attack through lack of data size check
28+
"GHSA-4hjh-wcwx-xvwj",
29+
// form-data uses unsafe random function in form-data for choosing boundary
30+
"GHSA-fjxv-7rqg-78g4"
3531
]
3632
}

foundry.toml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,14 +30,12 @@ compilation_restrictions = [
3030
skip = ['test/*']
3131

3232
[profile.test]
33-
inherit = "default"
3433
optimizer = false
3534
additional_compiler_profiles = []
3635
compilation_restrictions = []
3736
skip = []
3837

3938
[profile.yul]
40-
inherit = "default"
4139
src = 'yul'
4240
out = 'out/yul'
4341
libs = ['node_modules', 'lib']

yarn.lock

Lines changed: 22 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -2170,6 +2170,16 @@ es-object-atoms@^1.0.0, es-object-atoms@^1.1.1:
21702170
dependencies:
21712171
es-errors "^1.3.0"
21722172

2173+
es-set-tostringtag@^2.1.0:
2174+
version "2.1.0"
2175+
resolved "https://registry.yarnpkg.com/es-set-tostringtag/-/es-set-tostringtag-2.1.0.tgz#f31dbbe0c183b00a6d26eb6325c810c0fd18bd4d"
2176+
integrity sha512-j6vWzfrGVfyXxge+O0x5sh6cvxAog0a/4Rdd2K36zCMV5eJ+/+tOAngRO8cODMNWbVRdVlmGZQL2YS3yR8bIUA==
2177+
dependencies:
2178+
es-errors "^1.3.0"
2179+
get-intrinsic "^1.2.6"
2180+
has-tostringtag "^1.0.2"
2181+
hasown "^2.0.2"
2182+
21732183
escalade@^3.1.1:
21742184
version "3.2.0"
21752185
resolved "https://registry.yarnpkg.com/escalade/-/escalade-3.2.0.tgz#011a3f69856ba189dffa7dc8fcce99d2a87903e5"
@@ -2656,12 +2666,14 @@ form-data@^2.2.0:
26562666
mime-types "^2.1.12"
26572667

26582668
form-data@^4.0.0:
2659-
version "4.0.0"
2660-
resolved "https://registry.yarnpkg.com/form-data/-/form-data-4.0.0.tgz#93919daeaf361ee529584b9b31664dc12c9fa452"
2661-
integrity sha512-ETEklSGi5t0QMZuiXoA/Q6vcnxcLQP5vdugSpuAyi6SVGi2clPPp+xgEhuMaHC+zGgn31Kd235W35f7Hykkaww==
2669+
version "4.0.4"
2670+
resolved "https://registry.yarnpkg.com/form-data/-/form-data-4.0.4.tgz#784cdcce0669a9d68e94d11ac4eea98088edd2c4"
2671+
integrity sha512-KrGhL9Q4zjj0kiUt5OO4Mr/A/jlI2jDYs5eHBpYHPcBEVSiipAvn2Ko2HnPe20rmcuuvMHNdZFp+4IlGTMF0Ow==
26622672
dependencies:
26632673
asynckit "^0.4.0"
26642674
combined-stream "^1.0.8"
2675+
es-set-tostringtag "^2.1.0"
2676+
hasown "^2.0.2"
26652677
mime-types "^2.1.12"
26662678

26672679
@@ -2766,7 +2778,7 @@ get-intrinsic@^1.1.3, get-intrinsic@^1.2.4:
27662778
has-symbols "^1.0.3"
27672779
hasown "^2.0.0"
27682780

2769-
get-intrinsic@^1.3.0:
2781+
get-intrinsic@^1.2.6, get-intrinsic@^1.3.0:
27702782
version "1.3.0"
27712783
resolved "https://registry.yarnpkg.com/get-intrinsic/-/get-intrinsic-1.3.0.tgz#743f0e3b6964a93a5491ed1bffaae054d7f98d01"
27722784
integrity sha512-9fSjSaos/fRIVIp+xSJlE6lfwhES7LNtKaCBIamHsjr2na1BiABJPo0mOjjz8GJDURarmCPGqaiVg5mfjb98CQ==
@@ -4421,12 +4433,13 @@ [email protected]:
44214433
integrity sha512-E5LDX7Wrp85Kil5bhZv46j8jOeboKq5JMmYM3gVGdGH8xFpPWXUMsNrlODCrkoxMEeNi/XZIwuRvY4XNwYMJpw==
44224434

44234435
sha.js@^2.4.0, sha.js@^2.4.11, sha.js@^2.4.8:
4424-
version "2.4.11"
4425-
resolved "https://registry.yarnpkg.com/sha.js/-/sha.js-2.4.11.tgz#37a5cf0b81ecbc6943de109ba2960d1b26584ae7"
4426-
integrity sha512-QMEp5B7cftE7APOjk5Y6xgrbWu+WkLVQwk8JNjZ8nKRciZaByEW6MubieAiToS7+dwvrjGhH8jRXz3MVd0AYqQ==
4436+
version "2.4.12"
4437+
resolved "https://registry.yarnpkg.com/sha.js/-/sha.js-2.4.12.tgz#eb8b568bf383dfd1867a32c3f2b74eb52bdbf23f"
4438+
integrity sha512-8LzC5+bvI45BjpfXU8V5fdU2mfeKiQe1D1gIMn7XUlF3OTUrpdJpPPH4EMAnF0DsHHdSZqCdSss5qCmJKuiO3w==
44274439
dependencies:
4428-
inherits "^2.0.1"
4429-
safe-buffer "^5.0.1"
4440+
inherits "^2.0.4"
4441+
safe-buffer "^5.2.1"
4442+
to-buffer "^1.2.0"
44304443

44314444
sha1@^1.1.1:
44324445
version "1.1.1"

0 commit comments

Comments
 (0)