Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The verifier repo. #13

Closed
wants to merge 1 commit into from
Closed

The verifier repo. #13

wants to merge 1 commit into from

Conversation

taotao-circle
Copy link
Contributor

This PR squash all change history of this repo for open source.

Copy link

Dependency Review

The following issues were found:
  • ❌ 7 vulnerable package(s)
  • ❌ 37 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 45 package(s) with unknown licenses.
See the Details below.

Vulnerabilities

k6/package-lock.json

NameVersionVulnerabilitySeverity
@babel/traverse7.20.1Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codecritical
webpack5.74.0Cross-realm object access in Webpack 5critical

package-lock.json

NameVersionVulnerabilitySeverity
@babel/traverse7.20.1Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codecritical
webpack5.74.0Cross-realm object access in Webpack 5critical
webpack5.68.0Cross-realm object access in Webpack 5critical
loader-utils1.4.0Prototype pollution in webpack loader-utilscritical
loader-utils2.0.2Prototype pollution in webpack loader-utilscritical
flat4.1.1flat vulnerable to Prototype Pollutioncritical
loader-utils1.2.3Prototype pollution in webpack loader-utilscritical
Only included vulnerabilities with severity critical or higher.

License Issues

k6/package-lock.json

PackageVersionLicenseIssue Type
k60.0.0AGPL-3.0Incompatible License
loadtest-commongit+ssh://[email protected]/circlefin/loadtest-common.git#b0484c126df06c765ba82cd5f145162ee19f2eccNullUnknown License

package-lock.json

PackageVersionLicenseIssue Type
@bcoe/v8-coverage0.2.3ISC AND MITIncompatible License
did-jwt-vc2.1.9Apache-2.0 AND ISCIncompatible License
language-subtag-registry0.3.21ODC-By-1.0Incompatible License
multiformats9.6.3Apache-2.0 AND MITIncompatible License
pako2.0.4MIT AND ZlibIncompatible License
pako1.0.11MIT AND ZlibIncompatible License
sha.js2.4.11BSD-3-Clause AND MITIncompatible License
sprintf-js1.0.3BSD-3-Clause AND BSD-3-Clause-ClearIncompatible License
ethereum-dappfile:packages/ethereum-dappNullUnknown License
solana-dappfile:packages/solana-dappNullUnknown License
ethereumfile:packages/ethereumNullUnknown License
iniparser1.0.5NullUnknown License
hardhat2.8.3NullUnknown License

packages/solana/Cargo.lock

PackageVersionLicenseIssue Type
autocfg1.0.1Apache-2.0 AND MITIncompatible License
base640.12.3Apache-2.0 AND MITIncompatible License
base640.13.0Apache-2.0 AND MITIncompatible License
block-buffer0.9.0Apache-2.0 AND MITIncompatible License
block-padding0.2.1Apache-2.0 AND MITIncompatible License
crypto-mac0.8.0Apache-2.0 AND MITIncompatible License
digest0.9.0Apache-2.0 AND MITIncompatible License
either1.6.1Apache-2.0 AND MITIncompatible License
getrandom0.1.16Apache-2.0 AND MITIncompatible License
hashbrown0.11.2Apache-2.0 AND MITIncompatible License
heck0.3.3Apache-2.0 AND MITIncompatible License
hermit-abi0.1.19Apache-2.0 AND MITIncompatible License
hmac0.8.1Apache-2.0 AND MITIncompatible License
lazy_static1.4.0Apache-2.0 AND MITIncompatible License
log0.4.14Apache-2.0 AND MITIncompatible License
num-derive0.3.3Apache-2.0 AND MITIncompatible License
num-traits0.2.14Apache-2.0 AND MITIncompatible License
opaque-debug0.3.0Apache-2.0 AND MITIncompatible License
rand0.7.3Apache-2.0 AND MITIncompatible License
rand_chacha0.2.2Apache-2.0 AND MITIncompatible License
rand_core0.5.1Apache-2.0 AND MITIncompatible License
rand_hc0.2.0Apache-2.0 AND MITIncompatible License
regex-syntax0.6.25Apache-2.0 AND MITIncompatible License
scopeguard1.1.0Apache-2.0 AND MITIncompatible License
serde_bytes0.11.5Apache-2.0 AND MITIncompatible License
toml0.5.8Apache-2.0 AND MITIncompatible License
yansi0.5.0Apache-2.0 AND MITIncompatible License

k6/package.json

PackageVersionLicenseIssue Type
k6^0.0.0AGPL-3.0Incompatible License
loadtest-commongit+ssh://[email protected]/circlefin/loadtest-common.git#b0484c126df06c765ba82cd5f145162ee19f2eccNullUnknown License
jsrsasign^10.5.26NullUnknown License
jsrsasign-util^1.0.5NullUnknown License
lodash^4.17.21NullUnknown License
source-map^0.7.4NullUnknown License

packages/verifier/package.json

PackageVersionLicenseIssue Type
@project-serum/borsh^0.2.5NullUnknown License
express-async-handler^1.2.0NullUnknown License
@types/bs58^4.0.4NullUnknown License
@types/cors^2.8.17NullUnknown License
@types/express^4.17.21NullUnknown License
@types/jest^29.5.12NullUnknown License
@types/jsonpath^0.2.4NullUnknown License
@types/lodash^4.17.6NullUnknown License
@types/mocha^10.0.7NullUnknown License
@types/morgan^1.9.9NullUnknown License
@types/node^20.14.9NullUnknown License
@types/node-fetch^2.6.11NullUnknown License
@types/supertest^6.0.2NullUnknown License
@types/uuid^10.0.0NullUnknown License
@typescript-eslint/eslint-plugin^7.14.1NullUnknown License
@typescript-eslint/parser^7.14.1NullUnknown License
lodash^4.17.21NullUnknown License
pkh-did-resolver^2.0.0NullUnknown License
secp256k1^5.0.0NullUnknown License

package.json

PackageVersionLicenseIssue Type
@types/secp256k1^4.0.6NullUnknown License

packages/ethereum-dapp/package.json

PackageVersionLicenseIssue Type
@types/react^17.0.0NullUnknown License
@types/react-dom^17.0.0NullUnknown License

packages/ethereum/package.json

PackageVersionLicenseIssue Type
@nomiclabs/hardhat-ethers^2.0.4NullUnknown License
@types/jest^27.4.0NullUnknown License
@types/node^17.0.16NullUnknown License
hardhat^2.8.2NullUnknown License

packages/examples/package.json

PackageVersionLicenseIssue Type
@types/node^16.11.11NullUnknown License
@typescript-eslint/eslint-plugin^5.5.0NullUnknown License
@typescript-eslint/parser^5.5.0NullUnknown License

packages/solana-dapp/package.json

PackageVersionLicenseIssue Type
@types/jest^27.4.0NullUnknown License
@types/node^16.11.22NullUnknown License
@types/react^17.0.39NullUnknown License
@types/react-dom^17.0.11NullUnknown License

packages/solana/package.json

PackageVersionLicenseIssue Type
@types/jest^27.4.0NullUnknown License
Allowed Licenses: BSD-1-Clause, BSD-2-Clause, BSD-3-Clause, MIT, MIT-0, Apache-1.1, Apache-2.0, Artistic-1.0, Artistic-2.0, PHP-3.0, PHP-3.01, PSF-2.0, Zlib, zlib-acknowledgement, BSL-1.0, OpenSSL, WTFPL, CC0-1.0, CC-PDDC, CC-BY-1.0, CC-BY-2.0, CC-BY-2.5, CC-BY-3.0, CC-BY-4.0, Unlicense, ISC, BlueOak-1.0.0, BSD-2-Clause-Patent, ADSL, Apache-2.0, APAFML, BSD-1-Clause, BSD-2-Clause, BSD-2-Clause-FreeBSD, BSD-2-Clause-NetBSD, BSD-2-Clause-Views, BSL-1.0, DSDP, ECL-1.0, ECL-2.0, ImageMagick, ISC, Linux-OpenIB, MIT, MIT-Modern-Variant, MS-PL, MulanPSL-1.0, Mup, PostgreSQL, Spencer-99, UPL-1.0, Xerox, 0BSD, AFL-1.1, AFL-1.2, AFL-2.0, AFL-2.1, AFL-3.0, AMDPLPA, AML, AMPAS, ANTLR-PD, ANTLR-PD-fallback, Apache-1.0, Apache-1.1, Artistic-2.0, Bahyph, Barr, BSD-3-Clause, BSD-3-Clause-Attribution, BSD-3-Clause-Clear, BSD-3-Clause-LBNL, BSD-3-Clause-Modification, BSD-3-Clause-No-Nuclear-License-2014, BSD-3-Clause-No-Nuclear-Warranty, BSD-3-Clause-Open-MPI, BSD-4-Clause, BSD-4-Clause-Shortened, BSD-4-Clause-UC, BSD-Source-Code, bzip2-1.0.5, bzip2-1.0.6, CC0-1.0, CNRI-Jython, CNRI-Python, CNRI-Python-GPL-Compatible, Cube, curl, eGenix, Entessa, FTL, HTMLTIDY, IBM-pibs, ICU, Info-ZIP, Intel, JasPer-2.0, Libpng, libpng-2.0, libtiff, LPPL-1.3c, MIT-0, MIT-advertising, MIT-open-group, MIT-CMU, MIT-enna, MIT-feh, MITNFA, MTLL, MulanPSL-2.0, Multics, Naumen, NCSA, Net-SNMP, NetCDF, NTP, OLDAP-2.0, OLDAP-2.0.1, OLDAP-2.1, OLDAP-2.2, OLDAP-2.2.1, OLDAP-2.2.2, OLDAP-2.3, OLDAP-2.4, OLDAP-2.5, OLDAP-2.6, OLDAP-2.7, OLDAP-2.8, OML, OpenSSL, PHP-3.0, PHP-3.01, Plexus, PSF-2.0, Python-2.0, Ruby, Saxpath, SGI-B-2.0, SMLNJ, SWL, TCL, TCP-wrappers, Unicode-DFS-2015, Unicode-DFS-2016, Unlicense, VSL-1.0, W3C, X11, XFree86-1.1, Xnet, xpp, Zlib, zlib-acknowledgement, ZPL-2.0, ZPL-2.1, AAL, Adobe-2006, Afmparse, Artistic-1.0, Artistic-1.0-cl8, Artistic-1.0-Perl, Beerware, blessing, Borceux, CECILL-B, ClArtistic, Condor-1.1, Crossword, CrystalStacker, diffmark, DOC, EFL-1.0, EFL-2.0, Fair, FSFUL, FSFULLR, Giftware, HPND, IJG, Leptonica, LPL-1.0, LPL-1.02, MirOS, mpich2, NASA-1.3, NBPL-1.0, Newsletr, NLPL, NRL, OGTSL, OLDAP-1.1, OLDAP-1.2, OLDAP-1.3, OLDAP-1.4, psutils, Qhull, Rdisc, RSA-MD, Spencer-86, Spencer-94, TU-Berlin-1.0, TU-Berlin-2.0, Vim, W3C-19980720, W3C-20150513, Wsuipa, WTFPL, xinetd, Zed, Zend-2.0, ZPL-1.1, GPL-2.0, GPL-2.0+, GPL-2.0-or-later, GPL-3.0, GPL-3.0+, GPL-3.0-or-later, LGPL-2.1, LGPL-2.1+, LGPL-2.1-or-later, LGPL-3.0, LGPL-3.0+, LGPL-3.0-or-later, MPL-1.1, MPL-2.0, MPL-2.0-no-copyleft-exception, CDDL-1.0, CDDL-1.1, CPL-1.0, IPL-1.0, EPL-1.0, EPL-2.0, Apache-1.0, CC-BY-SA-1.0, CC-BY-SA-2.0
Excluded from license check: pkg:npm/borsh

Scanned Manifest Files

.github/workflows/basic.yml
  • circlefin/circle-public-github-workflows/.github/workflows/attach-release-assets.yaml@1.*.*
  • circlefin/circle-public-github-workflows/.github/workflows/pr-scan.yaml@1.*.*
k6/package-lock.json
k6/package.json
  • jsrsasign@^10.5.26
  • @babel/core@^7.18.5
  • babel-loader@^8.2.5
  • copy-webpack-plugin@^11.0.0
  • js-yaml@^4.1.0
  • jsrsasign-util@^1.0.5
  • jwt-decode@^3.1.2
  • k6@^0.0.0
  • loadtest-common@git+ssh://[email protected]/circlefin/loadtest-common.git#b0484c126df06c765ba82cd5f145162ee19f2ecc
  • lodash@^4.17.21
  • [email protected]
  • source-map@^0.7.4
  • terser-webpack-plugin@^5.3.3
  • webpack@^5.73.0
  • webpack-cli@^4.10.0
  • webpack-glob-entries@^1.0.1
package-lock.json
package.json
  • @types/secp256k1@^4.0.6
packages/ethereum-dapp/package.json
packages/ethereum/package.json
  • @babel/preset-typescript@^7.16.7
  • @nomiclabs/hardhat-ethers@^2.0.4
  • @openzeppelin/contracts@^4.4.2
  • @typechain/ethers-v5@^9.0.0
  • @typechain/hardhat@^4.0.0
  • @types/jest@^27.4.0
  • @types/node@^17.0.16
  • dotenv@^16.0.0
  • eslint@^8.4.0
  • eslint-config-prettier@^8.3.0
  • eslint-import-resolver-typescript@^2.5.0
  • eslint-plugin-import@^2.25.3
  • ethers@^5.5.4
  • hardhat@^2.8.2
  • jest@^27.5.0
  • prettier@^2.5.1
  • ts-node@^10.5.0
  • typechain@^7.0.0
  • typescript@^4.5.5
  • verifier@
packages/examples/package.json
  • @types/node@^16.11.11
  • @typescript-eslint/eslint-plugin@^5.5.0
  • @typescript-eslint/parser@^5.5.0
  • cross-fetch@^3.1.4
  • eslint@^8.4.0
  • eslint-config-prettier@^8.3.0
  • eslint-import-resolver-typescript@^2.5.0
  • eslint-plugin-import@^2.25.3
  • jose@^4.4.0
  • prettier@^2.5.1
  • ts-node@^10.4.0
  • typescript@^4.5.2
  • verifier@
packages/solana-dapp/package.json
  • @solana/wallet-adapter-base@^0.9.3
  • @solana/wallet-adapter-react@^0.15.3
  • @solana/wallet-adapter-react-ui@^0.9.5
  • @solana/wallet-adapter-wallets@^0.15.3
  • @solana/web3.js@^1.33.0
  • @testing-library/jest-dom@^5.16.2
  • @testing-library/react@^12.1.2
  • @testing-library/user-event@^13.5.0
  • @types/jest@^27.4.0
  • @types/node@^16.11.22
  • @types/react@^17.0.39
  • @types/react-dom@^17.0.11
  • crypto-browserify@^3.12.0
  • did-jwt-vc@^2.1.9
  • ethers@^5.5.4
  • process@^0.11.10
  • react@^17.0.2
  • react-app-rewired@^2.1.11
  • react-dom@^17.0.2
  • [email protected]
  • source-map-loader@^3.0.1
  • typescript@^4.5.5
  • web-vitals@^2.1.4
packages/solana/Cargo.lock
packages/solana/package.json
  • @babel/core@^7.17.0
  • @babel/preset-env@^7.16.11
  • @babel/preset-typescript@^7.16.7
  • @project-serum/anchor@^0.20.1
  • @types/jest@^27.4.0
  • ethers@^5.5.4
  • jest@^27.5.0
  • typescript@^4.3.5
packages/solana/programs/verity/Cargo.toml
  • anchor-lang@>= 0.20.1, < 0.21.0
  • solana-program@>= 1.9.4, < 2.0.0
packages/verifier/package.json
  • @aws-sdk/client-ssm@^3.603.0
  • @opentelemetry/api@^1.9.0
  • @opentelemetry/auto-instrumentations-node@^0.47.1
  • @opentelemetry/exporter-trace-otlp-grpc@^0.52.1
  • @opentelemetry/exporter-trace-otlp-http@^0.52.1
  • @opentelemetry/instrumentation@^0.52.1
  • @opentelemetry/resources@^1.25.1
  • @opentelemetry/sdk-node@^0.52.1
  • @opentelemetry/semantic-conventions@^1.25.1
  • @opentelemetry/tracing@^0.24.0
  • @prisma/client@^5.16.1
  • @prisma/instrumentation@^5.16.1
  • @project-serum/borsh@^0.2.5
  • @solana/web3.js@^1.93.3
  • @transmute/did-key.js@^0.3.0-unstable.10
  • @types/bs58@^4.0.4
  • @types/cors@^2.8.17
  • @types/express@^4.17.21
  • @types/jest@^29.5.12
  • @types/jsonpath@^0.2.4
  • @types/lodash@^4.17.6
  • @types/mocha@^10.0.7
  • @types/morgan@^1.9.9
  • @types/node@^20.14.9
  • @types/node-fetch@^2.6.11
  • @types/supertest@^6.0.2
  • @types/uuid@^10.0.0
  • @typescript-eslint/eslint-plugin@^7.14.1
  • @typescript-eslint/parser@^7.14.1
  • ajv@^8.16.0
  • bit-buffers@^1.0.2
  • bn.js@^5.2.1
  • body-parser@^1.20.2
  • bs58@^6.0.0
  • cors@^2.8.5
  • cross-fetch@^4.0.0
  • did-jwt@^8.0.4
  • did-jwt-vc@^4.0.4
  • did-resolver@^4.1.0
  • dotenv@^16.4.5
  • ejs@^3.1.10
  • eslint@^8.56.0
  • eslint-config-prettier@^9.1.0
  • eslint-import-resolver-typescript@^3.6.1
  • eslint-plugin-import@^2.29.1
  • ethers@^6.13.1
  • express@^4.19.2
  • express-async-handler@^1.2.0
  • helmet@^7.1.0
  • hot-shots@^10.0.0
  • jest@^29.7.0
  • js-sha3@^0.9.3
  • jsonpath@^1.1.1
  • lodash@^4.17.21
  • minify@^11.2.1
  • morgan@^1.10.0
  • nock@^13.5.4
  • nodemon@^3.1.4
  • npm-run-all@^4.1.5
  • pg@^8.12.0
  • pkh-did-resolver@^2.0.0
  • prettier@^3.3.2
  • prisma@^5.16.1
  • regenerator-runtime@^0.14.1
  • secp256k1@^5.0.0
  • supertest@^7.0.0
  • ts-jest@^29.1.5
  • ts-node@^10.9.2
  • typescript@^5.5.2
  • uuid@^10.0.0
  • web-did-resolver@^2.0.27
  • winston@^3.13.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants