Skip to content

fix(deps): pin dependencies#12

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dependencies-non-major
Open

fix(deps): pin dependencies#12
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dependencies-non-major

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Jan 8, 2024

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Age Confidence
@ls-lint/ls-lint pnpm.catalog.default pin ^2.3.12.3.1 age confidence
@monodon/rust pnpm.catalog.default pin ^2.3.02.3.0 age confidence
@napi-rs/cli (source) pnpm.catalog.default pin ^3.5.03.6.2 age confidence
@napi-rs/wasm-runtime (source) pnpm.catalog.default pin ^1.1.01.1.4 age confidence
@nx/devkit (source) pnpm.catalog.default minor 22.3.122.7.3 age confidence
@nx/eslint-plugin (source) pnpm.catalog.default minor 22.3.122.7.3 age confidence
@nx/jest (source) pnpm.catalog.default minor 22.3.122.7.3 age confidence
@nx/js (source) pnpm.catalog.default minor 22.3.122.7.3 age confidence
@nx/plugin (source) pnpm.catalog.default minor 22.3.122.7.3 age confidence
@nx/react (source) pnpm.catalog.default minor 22.3.122.7.3 age confidence
@nx/storybook (source) pnpm.catalog.default minor 22.3.122.7.3 age confidence
@nx/vite (source) pnpm.catalog.default minor 22.3.122.7.3 age confidence
@nx/web (source) pnpm.catalog.default minor 22.3.122.7.3 age confidence
@nx/workspace (source) pnpm.catalog.default minor 22.3.122.7.3 age confidence
@oxc-project/runtime (source) pnpm.catalog.default pin ^0.97.00.97.0 age confidence
@powerlines/nx (source) pnpm.catalog.default pin ^0.10.680.10.68 age confidence
@powerlines/plugin-env (source) pnpm.catalog.default pin ^0.13.640.13.106 age confidence
@powerlines/plugin-plugin (source) pnpm.catalog.default pin ^0.12.270.12.27 age confidence
@powerlines/plugin-react (source) pnpm.catalog.default pin ^0.1.580.1.596 age confidence
@powerlines/plugin-tsup (source) pnpm.catalog.default pin ^0.12.670.12.520 age confidence
@powerlines/plugin-untyped (source) pnpm.catalog.default pin ^0.2.80.2.478 age confidence
@powerlines/plugin-vite (source) pnpm.catalog.default pin ^0.14.580.14.517 age confidence
@powerlines/tsconfig (source) pnpm.catalog.default pin ^0.2.430.2.43 age confidence
@storm-software/config (source) pnpm.catalog.default pin ^1.134.721.134.72 age confidence
@storm-software/config-tools (source) pnpm.catalog.default pin ^1.188.721.188.72 age confidence
@storm-software/cspell (source) pnpm.catalog.default pin ^0.45.710.45.71 age confidence
@storm-software/esbuild (source) pnpm.catalog.default pin ^0.53.600.53.190 age confidence
@storm-software/eslint (source) pnpm.catalog.default pin ^0.169.730.169.73 age confidence
@storm-software/git-tools (source) pnpm.catalog.default pin ^2.124.552.124.55 age confidence
@storm-software/linting-tools (source) pnpm.catalog.default pin ^1.132.721.132.72 age confidence
@storm-software/markdownlint (source) pnpm.catalog.default pin ^0.30.710.30.71 age confidence
@storm-software/pnpm-tools (source) pnpm.catalog.default pin ^0.6.740.6.74 age confidence
@storm-software/prettier (source) pnpm.catalog.default pin ^0.57.710.57.71 age confidence
@storm-software/testing-tools (source) pnpm.catalog.default pin ^1.119.601.119.182 age confidence
@storm-software/tsdoc (source) pnpm.catalog.default pin ^0.13.710.13.71 age confidence
@storm-software/unbuild (source) pnpm.catalog.default pin ^0.57.600.57.190 age confidence
@storm-software/untyped (source) pnpm.catalog.default pin ^0.24.530.24.53 age confidence
@storm-software/workspace-tools (source) pnpm.catalog.default pin ^1.294.181.294.18 age confidence
@stryke/convert (source) pnpm.catalog.default pin ^0.6.230.6.58 age confidence
@stryke/crypto (source) pnpm.catalog.default pin ^0.5.240.5.44 age confidence
@stryke/fs (source) pnpm.catalog.default pin ^0.33.190.33.76 age confidence
@stryke/helpers (source) pnpm.catalog.default pin ^0.9.250.9.51 age confidence
@stryke/path (source) pnpm.catalog.default pin ^0.22.100.22.13 age confidence
@stryke/type-checks (source) pnpm.catalog.default pin ^0.5.80.5.41 age confidence
@stryke/types (source) pnpm.catalog.default pin ^0.10.220.10.53 age confidence
@stryke/url (source) pnpm.catalog.default pin ^0.3.140.3.39 age confidence
@swc-node/register pnpm.catalog.default pin ^1.11.11.11.1 age confidence
@swc/core (source) pnpm.catalog.default pin ^1.15.31.15.40 age confidence
@swc/helpers (source) pnpm.catalog.default pin ^0.5.170.5.21 age confidence
@taplo/cli (source) pnpm.catalog.default pin ^0.7.00.7.0 age confidence
@types/estree (source) pnpm.catalog.default pin ^1.0.81.0.9 age confidence
@types/jest (source) pnpm.catalog.default pin ^30.0.030.0.0 age confidence
@types/node (source) pnpm.catalog.default minor 20.9.020.19.41 age confidence
@types/react (source) pnpm.catalog.default pin ^19.2.719.2.15 age confidence
@types/react-dom (source) pnpm.catalog.default pin ^19.2.319.2.3 age confidence
@vitest/ui (source) pnpm.catalog.default pin ^3.2.43.2.4 age confidence
@vscode/vsce (source) dependencies minor 2.21.12.32.0 age confidence
GitGuardian/ggshield action minor v1.39.0v1.50.4 age confidence
backtrace workspace.dependencies pin 0.3.71=0.3.71 age confidence
bentocache dependencies minor 1.0.0-beta.71.6.1 age confidence
cacache workspace.dependencies pin 13.0.0=13.0.0 age confidence
colored workspace.dependencies pin 2.1.0=2.1.0 age confidence
copyfiles pnpm.catalog.default pin ^2.4.12.4.1 age confidence
defu pnpm.catalog.default pin ^6.1.46.1.4 age confidence
directories workspace.dependencies pin 5.0.1=5.0.1 age confidence
es-module-lexer pnpm.catalog.default pin ^1.7.01.7.0 age confidence
eslint (source) pnpm.catalog.default pin ^9.39.19.39.4 age confidence
eslint-flat-config-utils pnpm.catalog.default pin ^2.1.42.1.4 age confidence
estree-walker pnpm.catalog.default pin ^3.0.33.0.3 age confidence
handlebars workspace.dependencies pin 6.3.2=6.3.2 age confidence
indexmap workspace.dependencies pin 2.2.6=2.2.6 age confidence
indoc workspace.dependencies pin 2.0.4=2.0.4 age confidence
itertools workspace.dependencies pin 0.12.1=0.12.1 age confidence
jest (source) pnpm.catalog.default pin ^30.2.030.4.2 age confidence
jest-environment-jsdom (source) pnpm.catalog.default pin ^30.2.030.4.1 age confidence
jest-environment-node (source) pnpm.catalog.default pin ^30.2.030.4.1 age confidence
jest-util (source) pnpm.catalog.default pin ^30.2.030.4.1 age confidence
jiti pnpm.catalog.default pin ^2.6.12.7.0 age confidence
jsonc-eslint-parser pnpm.catalog.default pin ^2.4.12.4.2 age confidence
langium (source) pnpm.catalog.default pin ^2.1.32.1.3 age confidence
lazy_static workspace.dependencies pin 1.4.0=1.4.0 age confidence
lefthook pnpm.catalog.default pin ^1.13.61.13.6 age confidence
log4brains (source) pnpm.catalog.default pin ^1.1.01.1.0 age confidence
magic-string pnpm.catalog.default pin ^0.30.210.30.21 age confidence
napi workspace.dependencies pin 2.10.2=2.10.2 age confidence
napi-build workspace.dependencies pin 2.0.1=2.0.1 age confidence
napi-derive workspace.dependencies pin 2.9.3=2.9.3 age confidence
node (source) minor 20.11.020.20.2 age confidence
nx (source) pnpm.catalog.default minor 22.3.122.7.3 age confidence
periscopic pnpm.catalog.default pin ^4.0.24.0.3 age confidence
pest (source) workspace.dependencies pin 2.7.8=2.7.8 age confidence
pest_derive (source) workspace.dependencies pin 2.7.8=2.7.8 age confidence
pnpm (source) packageManager minor 10.26.010.33.4 age confidence
pnpm (source) uses-with minor 8.10.28.15.9 age confidence
powerlines (source) pnpm.catalog.default pin ^0.30.130.30.13 age confidence
prettier (source) pnpm.catalog.default pin ^3.7.43.8.3 age confidence
prettier (source) dependencies minor ^3.7.4^3.8.3 age confidence
prettier-plugin-prisma pnpm.catalog.default pin ^5.0.05.0.0 age confidence
prettier-plugin-tailwindcss pnpm.catalog.default pin ^0.5.140.5.14 age confidence
prost workspace.dependencies pin 0.12.3=0.12.3 age confidence
prost-types workspace.dependencies pin 0.12.3=0.12.3 age confidence
protoc-bin-vendored workspace.dependencies pin 3.0.0=3.0.0 age confidence
react (source) pnpm.catalog.default pin ^19.2.119.2.6 age confidence
react (source) peerDependencies minor 18.2.018.3.1 age confidence
react (source) dependencies minor 18.2.018.3.1 age confidence
react-dom (source) pnpm.catalog.default pin ^19.2.119.2.6 age confidence
react-dom (source) peerDependencies minor 18.2.018.3.1 age confidence
react-dom (source) dependencies minor 18.2.018.3.1 age confidence
rimraf pnpm.catalog.default pin ^5.0.105.0.10 age confidence
rsc-html-stream pnpm.catalog.default pin ^0.0.70.0.7 age confidence
rust (source, changelog) toolchain minor 1.91.11.95.0 age confidence
serde (source) workspace.dependencies pin 1.0.197=1.0.197 age confidence
serde_derive (source) workspace.dependencies pin 1.0.197=1.0.197 age confidence
serde_json workspace.dependencies pin 1.0.115=1.0.115 age confidence
sherif pnpm.catalog.default pin ^1.9.01.11.1 age confidence
signal-exit pnpm.catalog.default pin ^4.1.04.1.0 age confidence
storm-config (source) workspace.dependencies pin 0.2.8=0.2.8 age confidence
storm-workspace (source) workspace.dependencies pin 0.19.59=0.19.59 age confidence
strum workspace.dependencies pin 0.27.2=0.27.2 age confidence
strum_macros workspace.dependencies pin 0.27.2=0.27.2 age confidence
styfle/cancel-workflow-action action minor 0.12.10.13.1 age confidence
tailwindcss (source) pnpm.catalog.default minor 3.2.73.4.19 age confidence
tempfile (source) workspace.dependencies pin 3.10.1=3.10.1 age confidence
thiserror workspace.dependencies pin 2.0.17=2.0.17 age confidence
tonic dependencies minor 0.11.00.14.0 age confidence
tonic workspace.dependencies pin 0.11.0=0.11.0 age confidence
tonic-build workspace.dependencies pin 0.11.0=0.11.0 age confidence
tonic-health dependencies minor 0.11.00.14.0 age confidence
tonic-reflection workspace.dependencies pin 0.6.0=0.6.0 age confidence
tonic-types dependencies minor 0.11.00.14.0 age confidence
tonic-web dependencies minor 0.11.00.14.0 age confidence
tower-http dependencies minor 0.5.20.6.0 age confidence
ts-node (source) pnpm.catalog.default pin ^10.9.210.9.2 age confidence
tslib (source) pnpm.catalog.default pin ^2.8.12.8.1 age confidence
tsup (source) pnpm.catalog.default minor 8.4.08.5.1 age confidence
tsx (source) pnpm.catalog.default pin ^4.21.04.22.3 age confidence
turbo-stream pnpm.catalog.default pin ^3.1.03.2.0 age confidence
typescript (source) pnpm.catalog.default pin ^5.9.35.9.3 age confidence
verdaccio (source) pnpm.catalog.default pin ^5.33.05.33.0 age confidence
vite (source) pnpm.catalog.default pin ^5.4.215.4.21 age confidence
vite-plugin-dts (

Note

PR body was truncated to here.

@renovate renovate Bot requested a review from sullivanpj as a code owner January 8, 2024 02:44
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from f1befb8 to e510e06 Compare February 12, 2024 02:25
stormie-bot
stormie-bot previously approved these changes Feb 12, 2024
@stormie-bot stormie-bot enabled auto-merge (squash) February 12, 2024 02:25
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Feb 12, 2024

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: npm fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

CVE: GHSA-m7jm-9gc2-mpf2 fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names (CRITICAL)

Affected versions: >= 5.0.0 < 5.3.5; >= 4.1.3 < 4.5.4

Patched version: 5.3.5

From: pnpm-lock.yamlnpm/fast-xml-parser@5.2.5

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/fast-xml-parser@5.2.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm buffer is 96.0% likely obfuscated

Confidence: 0.96

Location: Package overview

From: pnpm-lock.yamlnpm/buffer@4.9.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/buffer@4.9.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm commander is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/commander@10.0.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/commander@10.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: pnpm-lock.yamlnpm/entities@4.5.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@4.5.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: pnpm-lock.yamlnpm/entities@6.0.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@6.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm es-module-lexer is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/es-module-lexer@2.0.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-module-lexer@2.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm es-module-lexer is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/es-module-lexer@2.0.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-module-lexer@2.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm execa is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/execa@9.6.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/execa@9.6.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm highlight.js is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/highlight.js@10.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/highlight.js@10.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm jiti is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/jiti@2.6.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jiti@2.6.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm json-schema is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/json-schema@0.4.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/json-schema@0.4.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm kind-of is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/kind-of@6.0.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/kind-of@6.0.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm node-fetch-native is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/node-fetch-native@1.6.7

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/node-fetch-native@1.6.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm rimraf is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/rimraf@5.0.10

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/rimraf@5.0.10. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from e510e06 to ce8d02f Compare February 19, 2024 02:10
stormie-bot
stormie-bot previously approved these changes Feb 19, 2024
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from ce8d02f to 8ddf8a7 Compare February 26, 2024 00:32
stormie-bot
stormie-bot previously approved these changes Feb 26, 2024
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from 8ddf8a7 to 1a704c6 Compare March 4, 2024 01:32
stormie-bot
stormie-bot previously approved these changes Mar 4, 2024
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from 1a704c6 to 45b9630 Compare March 11, 2024 00:52
stormie-bot
stormie-bot previously approved these changes Mar 11, 2024
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from 45b9630 to 1b332cb Compare March 18, 2024 01:40
stormie-bot
stormie-bot previously approved these changes Mar 18, 2024
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from 1b332cb to 1ac724a Compare March 25, 2024 01:49
stormie-bot
stormie-bot previously approved these changes Mar 25, 2024
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from 1ac724a to 32494b9 Compare April 1, 2024 00:37
stormie-bot
stormie-bot previously approved these changes Apr 1, 2024
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from 32494b9 to bf42e4f Compare April 8, 2024 01:15
stormie-bot
stormie-bot previously approved these changes Apr 8, 2024
@renovate renovate Bot force-pushed the renovate/dependencies-non-major branch from 535ea08 to b8aafdd Compare October 21, 2024 01:54
stormie-bot
stormie-bot previously approved these changes Oct 21, 2024
stormie-bot
stormie-bot previously approved these changes Oct 28, 2024
stormie-bot
stormie-bot previously approved these changes Nov 4, 2024
Copy link
Copy Markdown
Member

@stormie-bot stormie-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review by ChatGPT

stormie-bot
stormie-bot previously approved these changes Nov 18, 2024
Copy link
Copy Markdown
Member

@stormie-bot stormie-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review by ChatGPT

stormie-bot
stormie-bot previously approved these changes Nov 25, 2024
Copy link
Copy Markdown
Member

@stormie-bot stormie-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review by ChatGPT

stormie-bot
stormie-bot previously approved these changes Dec 2, 2024
Copy link
Copy Markdown
Member

@stormie-bot stormie-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review by ChatGPT

stormie-bot
stormie-bot previously approved these changes Dec 9, 2024
Copy link
Copy Markdown
Member

@stormie-bot stormie-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review by ChatGPT

stormie-bot
stormie-bot previously approved these changes Dec 16, 2024
Copy link
Copy Markdown
Member

@stormie-bot stormie-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review by ChatGPT

stormie-bot
stormie-bot previously approved these changes Dec 23, 2024
Copy link
Copy Markdown
Member

@stormie-bot stormie-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review by ChatGPT

stormie-bot
stormie-bot previously approved these changes Dec 30, 2024
Copy link
Copy Markdown
Member

@stormie-bot stormie-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review by ChatGPT

stormie-bot
stormie-bot previously approved these changes Dec 30, 2024
Copy link
Copy Markdown
Member

@stormie-bot stormie-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review by ChatGPT

stormie-bot
stormie-bot previously approved these changes Jan 13, 2025
Copy link
Copy Markdown
Member

@stormie-bot stormie-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review by ChatGPT

stormie-bot
stormie-bot previously approved these changes Jan 20, 2025
Copy link
Copy Markdown
Member

@stormie-bot stormie-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review by ChatGPT

@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Dec 29, 2025

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: Cargo.lock
Command failed: cargo update --config net.git-fetch-with-cli=true --manifest-path Cargo.toml --workspace
error: failed to load manifest for workspace member `/tmp/renovate/repos/github/storm-software/acidic/apps/engine`
referenced by workspace at `/tmp/renovate/repos/github/storm-software/acidic/Cargo.toml`

Caused by:
  failed to load manifest for dependency `acidic-config`

Caused by:
  failed to read `/tmp/renovate/repos/github/storm-software/acidic/crates/config/Cargo.toml`

Caused by:
  No such file or directory (os error 2)

File name: Cargo.lock
Command failed: cargo update --config net.git-fetch-with-cli=true --manifest-path apps/engine/Cargo.toml --workspace
error: failed to load manifest for workspace member `/tmp/renovate/repos/github/storm-software/acidic/apps/engine`
referenced by workspace at `/tmp/renovate/repos/github/storm-software/acidic/Cargo.toml`

Caused by:
  failed to load manifest for dependency `acidic-config`

Caused by:
  failed to read `/tmp/renovate/repos/github/storm-software/acidic/crates/config/Cargo.toml`

Caused by:
  No such file or directory (os error 2)

@deepsource-io
Copy link
Copy Markdown

deepsource-io Bot commented Dec 29, 2025

DeepSource Code Review

We reviewed changes in fb59a67...cbbfa5f on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
JavaScript May 25, 2026 1:39a.m. Review ↗
Shell May 25, 2026 1:39a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@socket-security
Copy link
Copy Markdown

socket-security Bot commented May 18, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednode-fetch@​3.3.26710010085100
Addedclsx@​2.1.11001009480100
Addedchalk@​5.6.210010010082100
Addedrimraf@​5.0.108710010083100
Addedcommander@​11.1.09810010084100
Addeddefu@​6.1.41008510086100
Addedpino-pretty@​10.3.19910010086100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant