Skip to content

fix: upgrade bn.js to 4.12.3/5.2.3#1631

Merged
ShubhamChaturvedi7 merged 1 commit intomasterfrom
CVE-2026-2739
Mar 2, 2026
Merged

fix: upgrade bn.js to 4.12.3/5.2.3#1631
ShubhamChaturvedi7 merged 1 commit intomasterfrom
CVE-2026-2739

Conversation

@ShubhamChaturvedi7
Copy link
Contributor

Issue #, if available:
#1630
Description of changes:

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Check any applicable:

  • Were any files moved? Moving files changes their URL, which breaks all hyperlinks to the files.

@ShubhamChaturvedi7 ShubhamChaturvedi7 requested a review from a team as a code owner February 25, 2026 00:37
Copy link
Contributor

@texastony texastony left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes LGTM.
Additionally, I searched the package-lock.json for "bn.js": "^4 and confirmed all hits were 4.12.3 or 5 something.

@CarlyG55
Copy link

CarlyG55 commented Mar 2, 2026

Hi, is there anything preventing this PR being merged and released? We're keen to get this bumped if not 🙂

@ShubhamChaturvedi7 ShubhamChaturvedi7 merged commit ebbd60f into master Mar 2, 2026
24 checks passed
@ShubhamChaturvedi7 ShubhamChaturvedi7 deleted the CVE-2026-2739 branch March 2, 2026 21:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants