Skip to content
This repository has been archived by the owner on Oct 18, 2019. It is now read-only.

Security/fix axios vuln #530

Merged
merged 1 commit into from May 31, 2019
Merged

Security/fix axios vuln #530

merged 1 commit into from May 31, 2019

Conversation

dannypaz
Copy link
Contributor

@dannypaz dannypaz commented May 31, 2019

Description

This PR fixes a security vuln with axios (introduced from our dependency on PM2).

Changes

  1. Updated PM2 to include axios fix

Related PRs

Axios update for pm2 keymetrics/pm2-io-js-api#65
Axios update axios/axios#2183

Todos

  • Tests
  • Documentation
  • Link to Trello

updated enum to have unknown default value

Fix - Error messaging for insufficient funds and filling orders (#522)

* added amounts for insufficient funds errors

* error logging for filling own order

added amounts for insufficient funds errors (#523)

updated enum to have unknown default value

add command to validate proto file and update circleci to check

added run: to circleci command

remove unused file

s

update circle config to install protoc

install protoc

try to update repos

try to fix apt-get

add protoc installation for circle ci

try new circle setup for protoc

added config

use unzip instead of tar

fix jessie for deps

added protoc check for circle ci

readd package command and remove apt-get install of protoc

stuff

all your protoc are belong to us

echo bash env

echo bash env

hail mary

use 64 instead

run file

remove help file

Fix/network status slow (#524)

* added amounts for insufficient funds errors

updated enum to have unknown default value

Fix - Error messaging for insufficient funds and filling orders (#522)

* added amounts for insufficient funds errors

* error logging for filling own order

add logs to check time for network status

added amounts for insufficient funds errors (#523)

updated enum to have unknown default value

add command to validate proto file and update circleci to check

added run: to circleci command

remove unused file

s

update circle config to install protoc

install protoc

try to update repos

try to fix apt-get

add protoc installation for circle ci

try new circle setup for protoc

added config

use unzip instead of tar

fix jessie for deps

added protoc check for circle ci

readd package command and remove apt-get install of protoc

stuff

all your protoc are belong to us

echo bash env

echo bash env

hail mary

use 64 instead

run file

remove help file

fix the way we inflate all block orders

add more logging for testing

edits to deadline for network status and removed dev logs from active fund calc

* added check for deadline params

* fix test with market

* change from string to number

* fix deadline usage in order summary and wallet

* fix tests for deadline changes

Feature/healthcheck json (#525)

* added amounts for insufficient funds errors

updated enum to have unknown default value

Fix - Error messaging for insufficient funds and filling orders (#522)

* added amounts for insufficient funds errors

* error logging for filling own order

added amounts for insufficient funds errors (#523)

updated enum to have unknown default value

add command to validate proto file and update circleci to check

added run: to circleci command

remove unused file

s

update circle config to install protoc

install protoc

try to update repos

try to fix apt-get

add protoc installation for circle ci

try new circle setup for protoc

added config

use unzip instead of tar

fix jessie for deps

added protoc check for circle ci

readd package command and remove apt-get install of protoc

stuff

all your protoc are belong to us

echo bash env

echo bash env

hail mary

use 64 instead

run file

remove help file

Fix/network status slow (#524)

* added amounts for insufficient funds errors

updated enum to have unknown default value

Fix - Error messaging for insufficient funds and filling orders (#522)

* added amounts for insufficient funds errors

* error logging for filling own order

add logs to check time for network status

added amounts for insufficient funds errors (#523)

updated enum to have unknown default value

add command to validate proto file and update circleci to check

added run: to circleci command

remove unused file

s

update circle config to install protoc

install protoc

try to update repos

try to fix apt-get

add protoc installation for circle ci

try new circle setup for protoc

added config

use unzip instead of tar

fix jessie for deps

added protoc check for circle ci

readd package command and remove apt-get install of protoc

stuff

all your protoc are belong to us

echo bash env

echo bash env

hail mary

use 64 instead

run file

remove help file

fix the way we inflate all block orders

add more logging for testing

edits to deadline for network status and removed dev logs from active fund calc

* added check for deadline params

* fix test with market

* change from string to number

* fix deadline usage in order summary and wallet

* fix tests for deadline changes

add json flag for healthcheck

* use logger instead of console and pretty print it

* added log check for healthcheck cli test

Version bump/0.7.1 beta (#526)

* 0.7.1-beta

* broker version change 0.7.1-beta

Feature - Add second parameter for range method calls (#529)

* added amounts for insufficient funds errors

updated enum to have unknown default value

Fix - Error messaging for insufficient funds and filling orders (#522)

* added amounts for insufficient funds errors

* error logging for filling own order

added amounts for insufficient funds errors (#523)

updated enum to have unknown default value

add command to validate proto file and update circleci to check

added run: to circleci command

remove unused file

s

update circle config to install protoc

install protoc

try to update repos

try to fix apt-get

add protoc installation for circle ci

try new circle setup for protoc

added config

use unzip instead of tar

fix jessie for deps

added protoc check for circle ci

readd package command and remove apt-get install of protoc

stuff

all your protoc are belong to us

echo bash env

echo bash env

hail mary

use 64 instead

run file

remove help file

Fix/network status slow (#524)

* added amounts for insufficient funds errors

updated enum to have unknown default value

Fix - Error messaging for insufficient funds and filling orders (#522)

* added amounts for insufficient funds errors

* error logging for filling own order

add logs to check time for network status

added amounts for insufficient funds errors (#523)

updated enum to have unknown default value

add command to validate proto file and update circleci to check

added run: to circleci command

remove unused file

s

update circle config to install protoc

install protoc

try to update repos

try to fix apt-get

add protoc installation for circle ci

try new circle setup for protoc

added config

use unzip instead of tar

fix jessie for deps

added protoc check for circle ci

readd package command and remove apt-get install of protoc

stuff

all your protoc are belong to us

echo bash env

echo bash env

hail mary

use 64 instead

run file

remove help file

fix the way we inflate all block orders

add more logging for testing

edits to deadline for network status and removed dev logs from active fund calc

* added check for deadline params

* fix test with market

* change from string to number

* fix deadline usage in order summary and wallet

* fix tests for deadline changes

Feature/healthcheck json (#525)

* added amounts for insufficient funds errors

updated enum to have unknown default value

Fix - Error messaging for insufficient funds and filling orders (#522)

* added amounts for insufficient funds errors

* error logging for filling own order

added amounts for insufficient funds errors (#523)

updated enum to have unknown default value

add command to validate proto file and update circleci to check

added run: to circleci command

remove unused file

s

update circle config to install protoc

install protoc

try to update repos

try to fix apt-get

add protoc installation for circle ci

try new circle setup for protoc

added config

use unzip instead of tar

fix jessie for deps

added protoc check for circle ci

readd package command and remove apt-get install of protoc

stuff

all your protoc are belong to us

echo bash env

echo bash env

hail mary

use 64 instead

run file

remove help file

Fix/network status slow (#524)

* added amounts for insufficient funds errors

updated enum to have unknown default value

Fix - Error messaging for insufficient funds and filling orders (#522)

* added amounts for insufficient funds errors

* error logging for filling own order

add logs to check time for network status

added amounts for insufficient funds errors (#523)

updated enum to have unknown default value

add command to validate proto file and update circleci to check

added run: to circleci command

remove unused file

s

update circle config to install protoc

install protoc

try to update repos

try to fix apt-get

add protoc installation for circle ci

try new circle setup for protoc

added config

use unzip instead of tar

fix jessie for deps

added protoc check for circle ci

readd package command and remove apt-get install of protoc

stuff

all your protoc are belong to us

echo bash env

echo bash env

hail mary

use 64 instead

run file

remove help file

fix the way we inflate all block orders

add more logging for testing

edits to deadline for network status and removed dev logs from active fund calc

* added check for deadline params

* fix test with market

* change from string to number

* fix deadline usage in order summary and wallet

* fix tests for deadline changes

add json flag for healthcheck

* use logger instead of console and pretty print it

* added log check for healthcheck cli test

Version bump/0.7.1 beta (#526)

* 0.7.1-beta

* broker version change 0.7.1-beta

allow parameters for range call

fixed variables for start finish

* rename rangeForBlockOrder to rangeForBlockOrderIds

* comment change of of

update pm2 to resolve axios vuln fix
@dannypaz
Copy link
Contributor Author

@dannypaz dannypaz merged commit 9b14deb into master May 31, 2019
@dannypaz dannypaz deleted the security/fix-axios-vuln branch May 31, 2019 18:45
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant