Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Some additional changes #81875

Open
wants to merge 4 commits into
base: main
Choose a base branch
from
Open

Some additional changes #81875

wants to merge 4 commits into from

Conversation

samczsun
Copy link
Collaborator

  • Delete local JavaScript files and re-export the TypeScript files
  • Run prettier on the entire repo
  • Update the issue template to encourage people to open one issue at a time instead of one issue per domain

Copy link

socket-security bot commented Sep 10, 2024

New dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@ethereumjs/[email protected] None 0 298 kB holgerd77
npm/@ethereumjs/[email protected] None 0 51.6 kB holgerd77
npm/@ethereumjs/[email protected] None 0 275 kB holgerd77
npm/@ethereumjs/[email protected] None 0 235 kB holgerd77
npm/@metamask/[email protected] None 0 320 kB metamaskbot
npm/@metamask/[email protected] None 0 245 kB danfinlay, gudahtt, kumavis, ...8 more
npm/@metamask/[email protected] None 0 10.8 kB mcmire
npm/@metamask/[email protected] None 0 321 kB lgbot
npm/@metamask/[email protected] None 0 292 kB lgbot
npm/@metamask/[email protected] None 0 296 kB danfinlay, gudahtt, kumavis, ...8 more
npm/@metamask/[email protected] None 0 437 kB metamaskbot
npm/@metamask/[email protected] None 0 695 kB metamaskbot
npm/@noble/[email protected] None 0 1.5 MB paulmillr
npm/@noble/[email protected] None 0 837 kB paulmillr
npm/@scure/[email protected] None 0 132 kB paulmillr
npm/@scure/[email protected] None 0 58.7 kB paulmillr
npm/@scure/[email protected] None 0 374 kB paulmillr
npm/@spruceid/[email protected] None 0 36.3 kB sbihel
npm/@types/[email protected] None 0 13.8 kB types
npm/@types/[email protected] None 0 6.45 kB types
npm/@types/[email protected] None 0 3.2 kB types
npm/[email protected] filesystem 0 1.46 MB ldthomas
npm/[email protected] None 0 99 kB fanatid
npm/[email protected] None 0 31 kB sheetjs
npm/[email protected] environment 0 42.1 kB qix
npm/[email protected] None 0 254 kB danfinlay
npm/[email protected] None 0 835 kB gudahtt
npm/[email protected] None 0 83.7 kB paulmillr
npm/[email protected] None 0 13 kB esp
npm/[email protected] None 0 9.44 kB hiddentao
npm/[email protected] None 0 199 kB 1api
npm/[email protected] environment 0 872 kB mweststrate
npm/[email protected] None 0 9.44 kB silentcicero
npm/[email protected] None 0 81.8 kB emn178
npm/[email protected] None 0 2.12 kB kumavis
npm/[email protected] network 0 12 kB paulmillr
npm/[email protected] None 0 6.72 kB styfle
npm/[email protected] None 0 23.9 kB voxpelli
npm/[email protected] environment, filesystem, unsafe 0 7.7 MB prettier-bot
npm/[email protected] None 0 95.8 kB npm-cli-ops
npm/[email protected] None 0 9.66 kB silentcicero
npm/[email protected] None 0 470 kB garycourt
npm/[email protected] None 0 123 kB ctavan
npm/[email protected] None 0 17.2 kB odysseas
npm/[email protected] None 0 6.46 kB raynos

View full report↗︎

Copy link

socket-security bot commented Sep 10, 2024

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring: npm/@metamask/[email protected], npm/@spruceid/[email protected], npm/[email protected]

View full report↗︎

Next steps

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/[email protected] or ignore all packages with @SocketSecurity ignore-all

@samczsun
Copy link
Collaborator Author

@SocketSecurity ignore npm/[email protected]
@SocketSecurity ignore npm/@metamask/[email protected]
@SocketSecurity ignore npm/@spruceid/[email protected]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant