Ensure Credo and React Native can use the latest cosmjs libraries

We got a security report because the cheqd SDK in Credo depends on two versions of cosmjs libraries.

One using recent cosmjs versions for ESM, and one using outdated cosmjs libraries which depends on a really old version of axios with critical vulnerabilities.

I want to open this bug report to track the progress of using the latest cosmjs libraries in Credo.

I think we will have to update Credo to use ESM, and thus also all projects and libraries depending on Credo, since cosmjs now only supports ESM.

I want to check whether we see other approaches besides Credo updating to ESM (I’ll try to prioritize it, but it will take a while to do this).

Upvoters
Status

Completed

Board
πŸ›

Bug Reports

Tags

Credo

Date

4 months ago

Author

Timo Glastra

Subscribe to post

Get notified by email when there are changes.