Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Sep 1, 2024

Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more here.

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, on day 1 of the month ( * 0-3 1 * * ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link

socket-security bot commented Sep 1, 2024

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednode-releases@​2.0.18 ⏵ 2.0.211001004487100
Updatedis-core-module@​2.15.1 ⏵ 2.16.167 +110082 +153100
Updated@​pkgr/​core@​0.1.1 ⏵ 0.2.9100 +110064 +185100
Updated@​babel/​helper-validator-option@​7.24.8 ⏵ 7.27.11001007191100
Updatedeslint-config-prettier@​9.1.0 ⏵ 9.1.21001007287100
Updated@​babel/​helper-validator-identifier@​7.24.7 ⏵ 7.27.11001007391100
Updated@​babel/​code-frame@​7.24.7 ⏵ 7.27.110010074 +192100
Updated@​babel/​helper-string-parser@​7.24.8 ⏵ 7.27.11001007491100
Updated@​changesets/​get-release-plan@​4.0.11 ⏵ 4.0.131001007487100
Updated@​babel/​helper-compilation-targets@​7.25.2 ⏵ 7.27.210010075 +192100
Updated@​openzeppelin/​docs-utils@​0.1.5 ⏵ 0.1.6751008783100
Updated@​babel/​helper-module-imports@​7.24.7 ⏵ 7.27.11001007591100
Updatedupdate-browserslist-db@​1.1.0 ⏵ 1.1.31001007580100
Updated@​frangio/​servbot@​0.2.5 ⏵ 0.3.0-176100100 +177 -1100
Updated@​babel/​template@​7.25.0 ⏵ 7.27.2100 +110076 +192100
Updatedcaniuse-lite@​1.0.30001651 ⏵ 1.0.30001745100 +110076 +197 +1100
Added@​babel/​helper-globals@​7.28.01001007688100
Updatedistanbul-reports@​3.1.7 ⏵ 3.2.0100 +11007786100
Updated@​babel/​helper-module-transforms@​7.25.2 ⏵ 7.28.3100 +110077 +193100
Updatedescalade@​3.1.2 ⏵ 3.2.0100 +1100100 +177100
Updated@​humanwhocodes/​config-array@​0.11.14 ⏵ 0.13.0100 +1100100 +178100
Updatedprocess-on-spawn@​1.0.0 ⏵ 1.1.01001008778100
Updated@​babel/​compat-data@​7.25.4 ⏵ 7.28.4100 +110078 +195100
Updatedimport-fresh@​3.3.0 ⏵ 3.3.1100 +110082 +378100
Updatedreusify@​1.0.4 ⏵ 1.1.010010010078100
Updatedjsesc@​2.5.2 ⏵ 3.1.010010010079100
Updatedpump@​3.0.0 ⏵ 3.0.3100 +110091 +479100
Updatedend-of-stream@​1.4.4 ⏵ 1.4.5100 +110084 +179100
Updatedchardet@​0.7.0 ⏵ 2.1.0100100100 +679100
Updated@​babel/​generator@​7.25.5 ⏵ 7.28.310010079 +294 -1100
Updated@​babel/​runtime@​7.27.1 ⏵ 7.28.41001007995100
Updatedresolve@​1.22.8 ⏵ 1.22.1099100100 +179100
See 32 more rows in the dashboard

View full report

@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from 3d33a5b to 76bcc7e Compare September 10, 2024 17:59
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 76bcc7e to a07dc72 Compare September 20, 2024 20:50
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from a07dc72 to 07c1934 Compare January 13, 2025 21:23
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 07c1934 to 1d25c19 Compare January 21, 2025 22:20
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 1d25c19 to 427d4e6 Compare March 19, 2025 20:39
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 427d4e6 to ccd0637 Compare April 14, 2025 14:42
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from ccd0637 to 51f385c Compare May 12, 2025 21:13
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 51f385c to 594665d Compare June 15, 2025 11:54
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from f49e021 to b009029 Compare August 13, 2025 17:13
Copy link

socket-security bot commented Aug 13, 2025

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Low
[email protected] is a AI-detected potential code anomaly.

Notes: No definitive malware detected in this fragment. The main security concern is supply-chain risk from dynamically loading plugins from potentially untrusted sources. To mitigate, enforce strict plugin provenance, disable remote plugin loading, verify plugin integrity, and apply least-privilege execution for plugins.

Confidence: 1.00

Severity: 0.60

From: package.jsonnpm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
[email protected] is a AI-detected potential code anomaly.

Notes: The module is a global hook that intercepts and allows modification of all child process spawns. The code itself is not overtly malicious (no embedded exfiltration or network code), but it creates a high-risk capability: listeners receive full environment and spawn metadata and can both read secrets and modify what is executed. If untrusted or malicious listeners can be registered, this becomes a significant supply-chain/backdoor risk. Recommend careful review of any code that registers listeners and restrict usage to trusted code only; consider whether such global monkey-patching is acceptable for your threat model.

Confidence: 1.00

Severity: 0.60

From: yarn.locknpm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from b009029 to 9f2c68a Compare August 19, 2025 17:14
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 9f2c68a to d5a7caf Compare August 31, 2025 12:50
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from d5a7caf to 7584431 Compare September 25, 2025 14:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants