fix: flatted vulnerability (GHSA-25h7-pfq9-p65f) (#1637)
Home /
Cardano Foundation /
cf-identity-wallet
Mar 07, 3-4 PM (0)
Mar 07, 4-5 PM (0)
Mar 07, 5-6 PM (0)
Mar 07, 6-7 PM (0)
Mar 07, 7-8 PM (0)
Mar 07, 8-9 PM (0)
Mar 07, 9-10 PM (0)
Mar 07, 10-11 PM (0)
Mar 07, 11-12 AM (0)
Mar 08, 12-1 AM (0)
Mar 08, 1-2 AM (0)
Mar 08, 2-3 AM (0)
Mar 08, 3-4 AM (0)
Mar 08, 4-5 AM (0)
Mar 08, 5-6 AM (0)
Mar 08, 6-7 AM (0)
Mar 08, 7-8 AM (0)
Mar 08, 8-9 AM (0)
Mar 08, 9-10 AM (0)
Mar 08, 10-11 AM (0)
Mar 08, 11-12 PM (0)
Mar 08, 12-1 PM (0)
Mar 08, 1-2 PM (0)
Mar 08, 2-3 PM (0)
Mar 08, 3-4 PM (0)
Mar 08, 4-5 PM (0)
Mar 08, 5-6 PM (0)
Mar 08, 6-7 PM (0)
Mar 08, 7-8 PM (0)
Mar 08, 8-9 PM (0)
Mar 08, 9-10 PM (0)
Mar 08, 10-11 PM (0)
Mar 08, 11-12 AM (0)
Mar 09, 12-1 AM (0)
Mar 09, 1-2 AM (0)
Mar 09, 2-3 AM (0)
Mar 09, 3-4 AM (2)
Mar 09, 4-5 AM (1)
Mar 09, 5-6 AM (0)
Mar 09, 6-7 AM (0)
Mar 09, 7-8 AM (0)
Mar 09, 8-9 AM (1)
Mar 09, 9-10 AM (1)
Mar 09, 10-11 AM (4)
Mar 09, 11-12 PM (0)
Mar 09, 12-1 PM (2)
Mar 09, 1-2 PM (1)
Mar 09, 2-3 PM (0)
Mar 09, 3-4 PM (0)
Mar 09, 4-5 PM (0)
Mar 09, 5-6 PM (0)
Mar 09, 6-7 PM (0)
Mar 09, 7-8 PM (0)
Mar 09, 8-9 PM (0)
Mar 09, 9-10 PM (0)
Mar 09, 10-11 PM (0)
Mar 09, 11-12 AM (0)
Mar 10, 12-1 AM (0)
Mar 10, 1-2 AM (0)
Mar 10, 2-3 AM (0)
Mar 10, 3-4 AM (0)
Mar 10, 4-5 AM (0)
Mar 10, 5-6 AM (0)
Mar 10, 6-7 AM (1)
Mar 10, 7-8 AM (0)
Mar 10, 8-9 AM (2)
Mar 10, 9-10 AM (0)
Mar 10, 10-11 AM (1)
Mar 10, 11-12 PM (1)
Mar 10, 12-1 PM (0)
Mar 10, 1-2 PM (0)
Mar 10, 2-3 PM (0)
Mar 10, 3-4 PM (0)
Mar 10, 4-5 PM (0)
Mar 10, 5-6 PM (0)
Mar 10, 6-7 PM (0)
Mar 10, 7-8 PM (0)
Mar 10, 8-9 PM (0)
Mar 10, 9-10 PM (0)
Mar 10, 10-11 PM (0)
Mar 10, 11-12 AM (0)
Mar 11, 12-1 AM (0)
Mar 11, 1-2 AM (0)
Mar 11, 2-3 AM (0)
Mar 11, 3-4 AM (0)
Mar 11, 4-5 AM (1)
Mar 11, 5-6 AM (0)
Mar 11, 6-7 AM (1)
Mar 11, 7-8 AM (1)
Mar 11, 8-9 AM (1)
Mar 11, 9-10 AM (5)
Mar 11, 10-11 AM (1)
Mar 11, 11-12 PM (0)
Mar 11, 12-1 PM (0)
Mar 11, 1-2 PM (0)
Mar 11, 2-3 PM (0)
Mar 11, 3-4 PM (1)
Mar 11, 4-5 PM (0)
Mar 11, 5-6 PM (0)
Mar 11, 6-7 PM (0)
Mar 11, 7-8 PM (0)
Mar 11, 8-9 PM (0)
Mar 11, 9-10 PM (0)
Mar 11, 10-11 PM (0)
Mar 11, 11-12 AM (0)
Mar 12, 12-1 AM (0)
Mar 12, 1-2 AM (0)
Mar 12, 2-3 AM (0)
Mar 12, 3-4 AM (0)
Mar 12, 4-5 AM (0)
Mar 12, 5-6 AM (0)
Mar 12, 6-7 AM (0)
Mar 12, 7-8 AM (1)
Mar 12, 8-9 AM (0)
Mar 12, 9-10 AM (1)
Mar 12, 10-11 AM (1)
Mar 12, 11-12 PM (0)
Mar 12, 12-1 PM (1)
Mar 12, 1-2 PM (1)
Mar 12, 2-3 PM (2)
Mar 12, 3-4 PM (3)
Mar 12, 4-5 PM (0)
Mar 12, 5-6 PM (0)
Mar 12, 6-7 PM (0)
Mar 12, 7-8 PM (0)
Mar 12, 8-9 PM (0)
Mar 12, 9-10 PM (0)
Mar 12, 10-11 PM (0)
Mar 12, 11-12 AM (0)
Mar 13, 12-1 AM (0)
Mar 13, 1-2 AM (0)
Mar 13, 2-3 AM (0)
Mar 13, 3-4 AM (0)
Mar 13, 4-5 AM (0)
Mar 13, 5-6 AM (0)
Mar 13, 6-7 AM (0)
Mar 13, 7-8 AM (0)
Mar 13, 8-9 AM (1)
Mar 13, 9-10 AM (0)
Mar 13, 10-11 AM (1)
Mar 13, 11-12 PM (2)
Mar 13, 12-1 PM (1)
Mar 13, 1-2 PM (1)
Mar 13, 2-3 PM (2)
Mar 13, 3-4 PM (2)
Mar 13, 4-5 PM (0)
Mar 13, 5-6 PM (0)
Mar 13, 6-7 PM (0)
Mar 13, 7-8 PM (0)
Mar 13, 8-9 PM (0)
Mar 13, 9-10 PM (0)
Mar 13, 10-11 PM (0)
Mar 13, 11-12 AM (0)
Mar 14, 12-1 AM (0)
Mar 14, 1-2 AM (0)
Mar 14, 2-3 AM (0)
Mar 14, 3-4 AM (0)
Mar 14, 4-5 AM (0)
Mar 14, 5-6 AM (0)
Mar 14, 6-7 AM (0)
Mar 14, 7-8 AM (0)
Mar 14, 8-9 AM (0)
Mar 14, 9-10 AM (1)
Mar 14, 10-11 AM (0)
Mar 14, 11-12 PM (0)
Mar 14, 12-1 PM (0)
Mar 14, 1-2 PM (0)
Mar 14, 2-3 PM (0)
Mar 14, 3-4 PM (0)
49 commits this week
Mar 07, 2026
-
Mar 14, 2026
fix: flatted vulnerability (GHSA-25h7-pfq9-p65f)
chore: vulnerability scanning updates (#1444)
* chore: ignore mostly irrelevant vulnerabilities for now and remove unneeded ones * chore(cred-serv): audit fixes * chore: update ignore list for osv scanner * chore(gha/depcheck): ignore osv-scanner dev depends until end of 01/2026 when they can be re-reviewed * chore(gha/depcheck-owasp): added owasp depcheck for package[-lock].json * chore(gha/depcheck-owasp): changed android specific job to scan any jar file in the repo/depends * chore(gha/depcheck-owasp): changed ios specific job to check Podfile.lock only (tho currently it checks zero depends for some reason) * chore(gha/depcheck-owasp): change android job to only look into jar files in android/ and node_modules/ * chore(gha/depcheck-owasp-ios): fix report upload * fix: package-lock.json * fix: resolve high-severity vulnerabilities for qs and axios * feat: update JavaScript dependencies to allow minor versions * fix: resolve production vulnerabilities and stabilize CI scanners * fix: resolve CI vulnerabilities and fix lockfile synchronization * fix: CI lockfile sync and OWASP dependency-check failures * fix: extend OSV scanner vulnerability ignore dates * feat: relax Appium dependency version constraints. * ifx: update dependency vulnerability suppression rules * fix: CI lockfile sync, OWASP scan failures, and configuration cleanup * fix: fix vulnerabilities and repair broken CI scans * fix: vulnerabilities and repair broken CI scans * fix: override dep @types/qs --------- Co-authored-by: Roberto C. Morano <[email protected]> Co-authored-by: J Caso <[email protected]>
test(e2e): PR review
fix: vulnerabilities and repair broken CI scans
fix: fix vulnerabilities and repair broken CI scans
fix: CI lockfile sync, OWASP scan failures, and configuration cleanup
ifx: update dependency vulnerability suppression rules
feat: relax Appium dependency version constraints.
fix: extend OSV scanner vulnerability ignore dates
Merge branch 'develop' of github.com:cardano-foundation/veridian-wallet into group-profiles-joiner
test(e2e): group profile setup as initiator (#1626)
* Add group profile onboarding E2E: feature files, remote-initiator helper, ssi-agent-urls * updated the helper, steps * updated the test * added contract * test: split group profile features and backend step definitions * chore(test): added createBackendUser and createRemoteInitiator interfaces * chore: add support for witness config * fixed getOObi, added agent role in init * chore: eventual acceptGroupInvitation fix * fix: Joiner business logic * fix: add endRole sign from remoteJoiner aafter group creation * test: normalize tests for Initiator creates multisig group and it becomes active * test: fix the step "all members accept the group invitation" * test(e2e): address PR comments --------- Co-authored-by: Ankit Shukla <[email protected]> Co-authored-by: Ankit Shukla <[email protected]> Co-authored-by: Ankit Shukla <[email protected]>
fix: CI lockfile sync and OWASP dependency-check failures
fix: resolve CI vulnerabilities and fix lockfile synchronization
fix: resolve production vulnerabilities and stabilize CI scanners
test(e2e): address PR comments
feat(e2e): add group-IPEX scenarios for initiator credential receive and present in 1-of-2 flow
feat: update JavaScript dependencies to allow minor versions
fix: resolve high-severity vulnerabilities for qs and axios
feat(ui): implement polling member statuses when issue or request group credential
chore(e2e): PR review
fix(ui): fix flickering to homepage while joining a group (#1633)
Co-authored-by: Sotatek-DukeVu <[email protected]>
fix(ui): Fix Animation and Vertical Centering in Credential Acceptance Screen (#1632)
* feat(ui): fix animation centering in credential acceptance screen * fix(ui): fix wrong translateY position when keyboard is showing * fix(ui): fix review comments --------- Co-authored-by: Sotatek-DukeVu <[email protected]>