Skip to content

Version Packages#14000

Merged
raymondjacobson merged 1 commit intomainfrom
changeset-release/main
Mar 30, 2026
Merged

Version Packages#14000
raymondjacobson merged 1 commit intomainfrom
changeset-release/main

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions bot commented Mar 24, 2026

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@audius/sdk@15.1.0

Minor Changes

  • 500dccb: Add artist coin solana connection flow

Patch Changes

  • d0f653d: Fix duplicate Bearer header prefix

@audius/sdk-legacy@6.0.26

Patch Changes

  • Updated dependencies [500dccb]
  • Updated dependencies [d0f653d]
    • @audius/sdk@15.1.0

@audius/sp-actions@1.0.30

Patch Changes

  • @audius/sdk-legacy@6.0.26

@audius/protocol-dashboard@0.1.16

Patch Changes

  • Updated dependencies [500dccb]
  • Updated dependencies [d0f653d]
    • @audius/sdk@15.1.0
    • @audius/sdk-legacy@6.0.26

@socket-security
Copy link
Copy Markdown

socket-security bot commented Mar 24, 2026

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Low
Potential code anomaly (AI signal): npm ws is 100.0% likely to have a medium risk anomaly

Notes: The code implements a standard EventTarget-like mixin for wrapping event listeners and dispatching events to user callbacks. There are no suspicious patterns such as dynamic code execution, hardcoded secrets, or network activity. The risk is contingent on what the consumer does inside their handlers; the snippet itself does not introduce malware or data leakage mechanisms beyond normal event dispatch. Overall security risk is low in isolation.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/ws@8.19.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ws@8.19.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm xmlbuilder is 100.0% likely to have a medium risk anomaly

Notes: The analyzed code is a standard XML writer base (XMLWriterBase) used to serialize XML node trees into strings. There is no concrete evidence of malicious behavior such as data exfiltration, reverse shells, or covert network activity within this fragment. The primary caveat is ensuring proper escaping of node values to prevent XML Injection in downstream consumers; otherwise, the module appears safe as a library component for XML generation.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/xmlbuilder@11.0.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/xmlbuilder@11.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions github-actions bot force-pushed the changeset-release/main branch 4 times, most recently from 888f314 to 987e65c Compare March 28, 2026 04:36
@github-actions github-actions bot force-pushed the changeset-release/main branch from 987e65c to 6c1aaaa Compare March 29, 2026 08:47
@raymondjacobson raymondjacobson merged commit 9dfdbfb into main Mar 30, 2026
2 of 3 checks passed
@raymondjacobson raymondjacobson deleted the changeset-release/main branch March 30, 2026 15:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant