[Snyk] Upgrade ethereumjs-wallet from 0.6.5 to 1.0.2 #7
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade ethereumjs-wallet from 0.6.5 to 1.0.2.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 3 versions ahead of your current version.
The recommended version was released 3 years ago.
Release notes
Package name: ethereumjs-wallet
Included Source Files
Source files from the
src
folder are now included in the distribution build. This allows for a better debugging experience in debug tools like Chrome DevTools by having working source map references to the original sources available for inspection.Wallet.fromV3()
andWallet.toV3()
triggered when using web bundlers using Buffer v4 shim (Webpack 4),see PR #135
This is the first
TypeScript
release on the library (thanks @ the-jackalope for the rewrite! ❤️), see PR #93 for the main PR here. The release comes with various breaking changes.Libray Import / API Documentation
The way submodules are exposed has been changed along the
TypeScript
rewrite and you will likely have to update your imports. Here is an example for thehdkey
submodule:Node.js / ES5:
ESM / TypeScript:
See README for examples on the other submodules.
Together with the switch to
TypeScript
the previously static documentation has been automated to now being generated withTypeDoc
to reflect all latest changes, see PR #98. See the new docs for an overview on theTypeScript
based API.API Changes
The API of the library hasn't been changed intentionally but has become more strict on type input by the explcit type definitions from the
TypeScript
code in function signatures together with the introduction of theethereumjs-util
v7 library within theWallet
library, which behaves more strict on type input on the various utility functions.This leads to cases where some input - while not having been the intended way to use the library - might have been worked before through implicit type conversion and is now not possible any more.
One example for this is the
Wallet.fromPublicKey()
function, here is the old code of the function:and here the new
TypeScript
code:This function worked in the
v0.6.x
version also with passing in a string, since theethereumjs-util
v6
importPublic
method converted the input implicitly to aBuffer
, thev1.0.0
version now directly enforces thefromPublicKey
input to be aBuffer
first hand.There will likely be more cases like this in the code since the type input of the library hasn't been documented in the older version. So we recommend here to go through all your function signature usages and see if you uses the correct input types. While a bit annoying this is a one-time task you will never have to do again since you can now profit from the clear
TypeScript
input types being both documented and enforced by theTypeScript
compiler.Pure JS Crypto Dependencies
This library now uses pure JS crypto dependencies which doesn't bring in the need for native compilation on installation. For
scrypt
key derivation scrypt-js from @ ricmoo is used (see PR #125).For BIP-32 key derivation the new ethereum-cryptography library is used which is a new Ethereum Foundation backed and formally audited libray to provide pure JS cryptographic primitives within the Ethereum ecosystem (see PR #128).
Removed ProviderEngine
Support for Provider Engine has been removed for security reasons, since the package is not very actively maintained and superseded by
json-rpc-engine
.If you need the removed functionality, it should be relatively easily possible to do this integration by adopting the code from provider-engine.ts.
See also: PR #117
Other Changes
Bug Fixes
salt
,iv
and/oruuid
options - being supplied as strings toWallet.toV3()
- could lead to errors during encryption and/or output that could not be decrypted, PR #95Refactoring & Maintenance
ES6
class rewrite, PR #93 (TypeScript
PR)ethereumjs-util
dependency fromv6
to [v7.0.2](https://github.com/ethereumjs/ethereumjs-util/releases/tag/v7.0.2 (stricter types), PR #126Wallet.deciperBuffer()
, PR #82Development & CI
ethereumjs-config
EthereumJS developer configuration standards, PR #93 (TypeScript
PR)hdkey
dependency with ethereum-cryptography that doesn't require native dependency compiling, PR #130Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: