Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 3 vulnerabilities #671

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

adamlaska
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • packages/components/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 631/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.2
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
Yes No Known Exploit
high severity 763/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.4
Path Traversal
SNYK-JS-WEBPACKDEVMIDDLEWARE-6476555
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @storybook/react The new version differs by 250 commits.
  • 829c72e v6.2.0
  • f8bfee0 Update root, peer deps, version.ts/json to 6.2.0
  • 2814acc CLI: Don't update versions.json on CLI prepare
  • 637daa1 Update 6.2 changelog
  • c760793 6.2 release
  • 5595b1e Merge pull request #14348 from gabiseabra/fix/issue_13771
  • a686a99 6.2.0-rc.13 next.json version file
  • 6be8b92 Update git head to 6.2.0-rc.13
  • c1dfd5b v6.2.0-rc.13
  • 4ef7b5a Update root, peer deps, version.ts/json to 6.2.0-rc.13
  • d954d50 6.2.0-rc.13 changelog
  • 1913c92 Merge pull request #14390 from YozhEzhi/patch-1
  • ee98e0e Merge branch 'next' of github.com:storybookjs/storybook into next
  • a8aadc4 Update CHANGELOG.md
  • 44eca58 Merge pull request #14392 from storybookjs/fix-raw-toggle
  • f10ef90 Merge pull request #14391 from YozhEzhi/patch-3
  • b1ee5e9 Prevent invalid initial color to be accepted as preset
  • 2c6b796 Color picker can't deal with 'transparent' keyword
  • 6951762 Don't show RAW toggle when data isn't representable by REJT
  • 259b12a Update my-component-story-use-globaltype.js.mdx
  • a8a846b Update my-component-story-use-globaltype.mdx.mdx
  • 57fc3cd 6.2.0-rc.12 next.json version file
  • ba0f535 Fix changelog
  • 6ec5750 Update git head to 6.2.0-rc.12

See the full diff

Package name: chromatic The new version differs by 250 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution
🦉 Path Traversal

Copy link

google-cla bot commented Mar 23, 2024

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@babel/runtime@7.4.3 None 0 86.1 kB nicolo-ribaudo
npm/@codesandbox/common@1.0.8 Transitive: environment, filesystem, unsafe +62 19.4 MB compuives
npm/@types/node@10.14.8 None 0 589 kB types
npm/@types/rimraf@2.0.2 None +3 21.8 kB types
npm/@types/semver@5.5.0 None 0 10 kB types
npm/alphanum-sort@1.0.2 None 0 6.4 kB trysound
npm/aproba@1.2.0 None 0 8.18 kB iarna
npm/are-we-there-yet@1.1.5 None +1 22.1 kB iarna
npm/array-uniq@1.0.3 None 0 3.57 kB sindresorhus
npm/assert-plus@1.0.0 environment 0 11.4 kB pfmooney
npm/axios@0.19.2 environment, network +1 366 kB emilyemorehouse
npm/babel-core@6.26.3 environment, filesystem, unsafe Transitive: network +10 313 kB loganfsmyth
npm/babel-generator@6.26.1 None +3 123 kB hzoo
npm/babel-plugin-emotion@9.2.10 filesystem Transitive: environment, network +7 582 kB mitchellhamilton
npm/babel-plugin-macros@2.5.1 None 0 54.1 kB kentcdodds
npm/babel-plugin-syntax-jsx@6.18.0 None 0 969 B hzoo
npm/babel-plugin-transform-class-properties@6.24.1 None +3 17.8 kB hzoo
npm/babel-plugin-transform-es2015-modules-amd@6.24.1 None 0 5.16 kB hzoo
npm/babel-plugin-transform-es2015-modules-commonjs@6.26.2 None +1 31.5 kB loganfsmyth
npm/babel-plugin-transform-flow-strip-types@6.22.0 None +1 4.92 kB hzoo
npm/babel-plugin-transform-runtime@6.23.0 None 0 17.7 kB loganfsmyth
npm/babel-preset-env@1.7.0 Transitive: environment, filesystem +40 391 kB existentialism
npm/babel-preset-flow@6.23.0 None 0 1.61 kB loganfsmyth
npm/babel-preset-react@6.24.1 None +6 71.2 kB hzoo
npm/babel-runtime@6.26.0 Transitive: eval +1 73.6 kB hzoo
npm/babel-template@6.26.0 None 0 5.73 kB hzoo
npm/babel-traverse@6.26.0 environment +5 261 kB hzoo
npm/babel-types@6.26.0 None +2 193 kB hzoo
npm/babylon@6.18.0 None 0 282 kB hzoo
npm/bn.js@4.11.8 None 0 99.4 kB indutny
npm/boolbase@1.0.0 None 0 1.33 kB feedic
npm/braces@2.3.2 None +2 83.7 kB jonschlinkert
npm/browserify-aes@1.2.0 None +1 34.6 kB cwmma
npm/browserslist@4.23.0 environment, filesystem +1 344 kB ai
npm/caniuse-db@1.0.30000875 None 0 9.29 MB fyrd
npm/caniuse-lite@1.0.30000874 None 0 1.21 MB ai
npm/chalk@2.4.2 environment +3 46 kB sindresorhus
npm/chownr@1.0.1 filesystem 0 2.67 kB isaacs
npm/cipher-base@1.0.4 None 0 7.95 kB cwmma
npm/code-point-at@1.1.0 None 0 2.99 kB sindresorhus
npm/color-convert@1.9.2 None 0 27 kB qix
npm/color-name@1.1.1 None 0 6.66 kB dfcreative
npm/color@0.11.4 None +1 30.8 kB qix
npm/combined-stream@1.0.6 None +1 19.1 kB alexindigo
npm/commander@2.17.1 filesystem, shell 0 61.2 kB abetomo
npm/component-emitter@1.2.1 None 0 7.57 kB nami-doc
npm/console-control-strings@1.1.0 None 0 12.7 kB iarna
npm/core-js@2.6.9 eval 0 2.26 MB zloirock
npm/core-util-is@1.0.2 None 0 23.2 kB isaacs
npm/cosmiconfig@5.2.0 filesystem +9 85.8 kB davidtheclark
npm/create-hash@1.2.0 None +2 18.8 kB cwmma
npm/create-hmac@1.1.7 None 0 5.81 kB cwmma
npm/css-color-names@0.0.4 None 0 5.33 kB bahamas10
npm/css-tree@1.0.0-alpha25 None 0 577 kB lahmatiy
npm/cssnano@4.0.5 Transitive: filesystem +15 232 kB evilebottnawi
npm/deep-extend@0.6.0 None 0 9.19 kB unclechu
npm/detect-libc@1.0.3 environment, filesystem, shell 0 17.2 kB lovell
npm/domelementtype@1.3.0 None 0 2.04 kB feedic
npm/electron-to-chromium@1.3.55 None 0 17.9 kB kilianvalkhof
npm/emotion@9.2.10 Transitive: environment +3 1.92 MB mitchellhamilton
npm/entities@1.1.1 None 0 55.7 kB feedic
npm/es-abstract@1.12.0 None +4 254 kB ljharb
npm/escape-string-regexp@1.0.5 None 0 2.69 kB jbnicolai
npm/escodegen@1.9.1 None +7 584 kB michaelficarra
npm/event-stream@3.3.4 None +6 104 kB dominictarr
npm/evp_bytestokey@1.0.3 None +2 18.7 kB dcousens
npm/extend@3.0.1 None 0 20.4 kB ljharb
npm/extsprintf@1.3.0 None 0 22.8 kB dap
npm/fs-minipass@1.2.5 filesystem 0 13 kB iarna
npm/function-bind@1.1.1 None 0 25.2 kB ljharb
npm/gauge@2.7.4 Transitive: environment +1 51.7 kB iarna
npm/get-value@2.0.6 None 0 3.71 kB jonschlinkert
npm/glob@7.1.4 filesystem Transitive: environment +4 79.8 kB isaacs
npm/graceful-fs@4.1.11 environment, filesystem 0 24.9 kB isaacs
npm/gsap@2.0.2 None 0 2.84 MB greensock
npm/has@1.0.3 None 0 2.77 kB ljharb
npm/hash.js@1.1.5 None 0 40.2 kB indutny
npm/iconv-lite@0.4.23 None 0 336 kB ashtuchkin
npm/ignore-walk@3.0.1 filesystem 0 10.8 kB isaacs
npm/inherits@2.0.3 None 0 3.82 kB isaacs
npm/ini@1.3.5 None 0 8.93 kB isaacs
npm/invariant@2.2.4 None 0 7.64 kB zertosh
npm/is-callable@1.1.4 None 0 30.6 kB ljharb
npm/is-descriptor@1.0.2 None +3 49.7 kB jonschlinkert
npm/is-extendable@0.1.1 None 0 5.09 kB jonschlinkert
npm/is-plain-object@2.0.4 None 0 7.5 kB jonschlinkert
npm/isarray@1.0.0 None 0 3.89 kB juliangruber
npm/isobject@3.0.1 None 0 6.93 kB doowb
npm/js-tokens@4.0.0 None 0 15.1 kB lydell
npm/js-yaml@3.13.1 eval Transitive: environment, filesystem +2 714 kB vitaly
npm/jsonc-parser@2.1.1 None 0 175 kB aeschli
npm/lodash@4.17.11 None 0 1.4 MB jdalton
npm/loose-envify@1.4.0 environment 0 5.81 kB zertosh
npm/mdn-data@1.1.4 None 0 481 kB mdn
npm/mime-types@2.1.18 None +1 183 kB dougwilson
npm/minimalistic-assert@1.0.1 None 0 1.55 kB cwmma
npm/minimalistic-crypto-utils@1.0.1 None 0 4.76 kB indutny
npm/minimatch@3.0.4 None +3 55.7 kB isaacs
npm/minipass@2.3.3 environment 0 13.8 kB isaacs
npm/minizlib@1.1.0 None 0 14.7 kB isaacs
npm/mkdirp@0.5.1 filesystem +1 42.5 kB substack
npm/nan@2.10.0 None 0 410 kB kkoopa
npm/needle@2.2.1 filesystem, network 0 198 kB tomas
npm/node-pre-gyp@0.10.3 environment, filesystem Transitive: shell +7 226 kB springmeyer
npm/node-releases@2.0.14 None 0 34 kB chicoxyzzy
npm/object-keys@1.0.12 None 0 28.2 kB ljharb
npm/once@1.4.0 None +1 7.01 kB isaacs
npm/os-tmpdir@1.0.2 None 0 3.06 kB sindresorhus
npm/parcel-bundler@1.9.7 environment, eval, filesystem, network, shell Transitive: unsafe +129 13 MB devongovett
npm/postcss@6.0.23 filesystem 0 658 kB ai
npm/process-nextick-args@2.0.0 None 0 3.14 kB cwmma
npm/request@2.85.0 environment, filesystem, network Transitive: eval +41 3.94 MB simov
npm/rimraf@2.6.3 filesystem 0 15.2 kB isaacs
npm/safe-buffer@5.1.2 None 0 31.7 kB feross
npm/semver@5.5.1 None 0 57.4 kB isaacs
npm/through@2.3.8 None 0 12.5 kB dominictarr
npm/through2@2.0.3 None +2 37.3 kB rvagg
npm/tweetnacl@0.14.5 None 0 174 kB dchest
npm/vinyl-fs@2.4.4 Transitive: environment, filesystem, unsafe +75 843 kB phated
npm/vinyl@0.4.6 None +1 25.9 kB fractal
npm/vscode-extension-telemetry@0.1.1 environment, filesystem Transitive: eval, network, shell, unsafe +4 798 kB sbatten
npm/vscode-nls@4.0.0 environment, filesystem 0 23.8 kB dbaeumer
npm/vscode@1.1.17 Transitive: environment, eval, filesystem, shell, unsafe +112 4.02 MB bpasero
npm/xtend@4.0.1 None 0 5.96 kB raynos

🚮 Removed packages: npm/@absinthe/socket@0.2.1, npm/@apollo/react-common@3.1.3, npm/@apollo/react-hooks@3.1.3, npm/@babel/cli@7.8.4, npm/@babel/code-frame@7.10.3, npm/@babel/generator@7.10.3, npm/@babel/helper-annotate-as-pure@7.8.3, npm/@babel/helper-builder-binary-assignment-operator-visitor@7.8.3, npm/@babel/helper-builder-react-jsx-experimental@7.9.5, npm/@babel/helper-builder-react-jsx@7.9.0, npm/@babel/helper-create-class-features-plugin@7.9.5, npm/@babel/helper-create-regexp-features-plugin@7.8.8, npm/@babel/helper-define-map@7.8.3, npm/@babel/helper-function-name@7.10.3, npm/@babel/helper-get-function-arity@7.10.3, npm/@babel/helper-member-expression-to-functions@7.8.3, npm/@babel/helper-module-imports@7.8.3, npm/@babel/helper-optimise-call-expression@7.8.3, npm/@babel/helper-plugin-utils@7.10.4, npm/@babel/helper-remap-async-to-generator@7.8.3, npm/@babel/helper-replace-supers@7.8.6, npm/@babel/helper-split-export-declaration@7.10.1, npm/@babel/helper-validator-identifier@7.10.4, npm/@babel/highlight@7.10.3, npm/@babel/parser@7.11.5, npm/@babel/plugin-proposal-async-generator-functions@7.8.3, npm/@babel/plugin-proposal-class-properties@7.8.3, npm/@babel/plugin-proposal-decorators@7.8.3, npm/@babel/plugin-proposal-dynamic-import@7.8.3, npm/@babel/plugin-proposal-json-strings@7.8.3, npm/@babel/plugin-proposal-nullish-coalescing-operator@7.8.3, npm/@babel/plugin-proposal-numeric-separator@7.8.3, npm/@babel/plugin-proposal-object-rest-spread@7.9.6, npm/@babel/plugin-proposal-optional-catch-binding@7.8.3, npm/@babel/plugin-proposal-optional-chaining@7.9.0, npm/@babel/plugin-proposal-unicode-property-regex@7.8.8, npm/@babel/plugin-syntax-async-generators@7.8.4, npm/@babel/plugin-syntax-bigint@7.8.3, npm/@babel/plugin-syntax-class-properties@7.8.3, npm/@babel/plugin-syntax-dynamic-import@7.8.3, npm/@babel/plugin-syntax-flow@7.8.3, npm/@babel/plugin-syntax-import-meta@7.10.4, npm/@babel/plugin-syntax-json-strings@7.8.3, npm/@babel/plugin-syntax-jsx@7.8.3, npm/@babel/plugin-syntax-logical-assignment-operators@7.8.3, npm/@babel/plugin-syntax-nullish-coalescing-operator@7.8.3, npm/@babel/plugin-syntax-numeric-separator@7.8.3, npm/@babel/plugin-syntax-object-rest-spread@7.8.3, npm/@babel/plugin-syntax-optional-catch-binding@7.8.3, npm/@babel/plugin-syntax-optional-chaining@7.8.3, npm/@babel/plugin-syntax-top-level-await@7.8.3, npm/@babel/plugin-syntax-typescript@7.8.3, npm/@babel/plugin-transform-arrow-functions@7.8.3, npm/@babel/plugin-transform-async-to-generator@7.8.3, npm/@babel/plugin-transform-block-scoped-functions@7.8.3, npm/@babel/plugin-transform-block-scoping@7.8.3, npm/@babel/plugin-transform-classes@7.9.5, npm/@babel/plugin-transform-computed-properties@7.8.3, npm/@babel/plugin-transform-destructuring@7.9.5, npm/@babel/plugin-transform-dotall-regex@7.8.3, npm/@babel/plugin-transform-duplicate-keys@7.8.3, npm/@babel/plugin-transform-exponentiation-operator@7.8.3, npm/@babel/plugin-transform-flow-strip-types@7.9.0, npm/@babel/plugin-transform-for-of@7.9.0, npm/@babel/plugin-transform-function-name@7.8.3, npm/@babel/plugin-transform-literals@7.8.3, npm/@babel/plugin-transform-member-expression-literals@7.8.3, npm/@babel/plugin-transform-modules-amd@7.9.6, npm/@babel/plugin-transform-modules-commonjs@7.9.6, npm/@babel/plugin-transform-modules-systemjs@7.9.6, npm/@babel/plugin-transform-modules-umd@7.9.0, npm/@babel/plugin-transform-named-capturing-groups-regex@7.8.3, npm/@babel/plugin-transform-new-target@7.8.3, npm/@babel/plugin-transform-object-super@7.8.3, npm/@babel/plugin-transform-parameters@7.9.5, npm/@babel/plugin-transform-property-literals@7.8.3, npm/@babel/plugin-transform-react-constant-elements@7.9.0, npm/@babel/plugin-transform-react-display-name@7.8.3, npm/@babel/plugin-transform-react-jsx-development@7.9.0, npm/@babel/plugin-transform-react-jsx-self@7.9.0, npm/@babel/plugin-transform-react-jsx-source@7.9.0, npm/@babel/plugin-transform-react-jsx@7.9.4, npm/@babel/plugin-transform-regenerator@7.8.7, npm/@babel/plugin-transform-reserved-words@7.8.3, npm/@babel/plugin-transform-runtime@7.9.0, npm/@babel/plugin-transform-shorthand-properties@7.8.3, npm/@babel/plugin-transform-spread@7.8.3, npm/@babel/plugin-transform-sticky-regex@7.8.3, npm/@babel/plugin-transform-template-literals@7.8.3, npm/@babel/plugin-transform-typeof-symbol@7.8.4, npm/@babel/plugin-transform-typescript@7.9.4, npm/@babel/plugin-transform-unicode-regex@7.8.3, npm/@babel/preset-env@7.9.0, npm/@babel/preset-flow@7.0.0, npm/@babel/preset-react@7.9.1, npm/@babel/preset-typescript@7.9.0, npm/@babel/register@7.13.16, npm/@babel/runtime-corejs3@7.19.4, npm/@babel/runtime@7.11.2, npm/@babel/template@7.10.3, npm/@babel/traverse@7.10.1, npm/@babel/types@7.11.5, npm/@bcoe/v8-coverage@0.2.3, npm/@chromaui/localtunnel@2.0.1, npm/@cnakazawa/watch@1.0.3, npm/@code-hike/classer@0.0.0-e48fa74, npm/@codemirror/autocomplete@0.19.15, npm/@codemirror/closebrackets@0.19.2, npm/@codemirror/commands@0.19.8, npm/@codemirror/comment@0.19.1, npm/@codemirror/gutter@0.19.9, npm/@codemirror/highlight@0.19.8, npm/@codemirror/history@0.19.2, npm/@codemirror/lang-css@0.19.3, npm/@codemirror/lang-html@0.19.4, npm/@codemirror/lang-javascript@0.19.7, npm/@codemirror/language@0.19.10, npm/@codemirror/matchbrackets@0.19.4, npm/@codemirror/rangeset@0.19.9, npm/@codemirror/state@0.19.9, npm/@codemirror/text@0.19.6, npm/@codemirror/tooltip@0.19.16, npm/@codemirror/view@0.19.48, npm/@codesandbox/ab@1.0.5, npm/@codesandbox/sandpack-client@1.12.1, npm/@codesandbox/sandpack-react@1.17.0, npm/@codesandbox/sandpack-themes@1.17.0, npm/@csstools/convert-colors@1.4.0, npm/@csstools/normalize.css@10.1.0, npm/@divyenduz/graphql-language-service-interface@1.2.7, npm/@divyenduz/graphql-language-service-server@1.2.3, npm/@divyenduz/graphql-language-service-utils@1.2.7, npm/@divyenduz/ts-graphql-plugin@0.1.0, npm/@emmetio/abbreviation@0.6.5, npm/@emmetio/codemirror-plugin@0.3.5, npm/@emmetio/output-renderer@0.1.2, npm/@emmetio/stream-reader@2.2.0, npm/@emotion/cache@10.0.27, npm/@emotion/core@10.0.35, npm/@emotion/css@10.0.27, npm/@emotion/is-prop-valid@0.8.6, npm/@emotion/styled-base@10.0.27, npm/@emotion/styled@10.0.27, npm/@eslint/eslintrc@0.1.3, npm/@essentials/request-timeout@1.0.1, npm/@gatsbyjs/relay-compiler@2.0.0-printer-fix.2, npm/@graphql-cli/common@4.0.0, npm/@graphql-cli/init@4.0.0, npm/@graphql-codegen/cli@1.15.4, npm/@graphql-codegen/fragment-matcher@1.15.4, npm/@graphql-codegen/typescript-graphql-files-modules@1.15.4, npm/@graphql-codegen/typescript-operations@1.15.4, npm/@graphql-codegen/typescript@1.15.4, npm/@graphql-toolkit/common@0.10.7, npm/@graphql-toolkit/schema-merging@0.10.7, npm/@graphql-tools/merge@6.0.10, npm/@graphql-tools/url-loader@6.0.10, npm/@graphql-tools/utils@6.0.10, npm/@hapi/address@2.0.0, npm/@hapi/bourne@1.3.2, npm/@hapi/hoek@8.2.1, npm/@hapi/joi@15.1.1, npm/@iarna/toml@2.2.3, npm/@icons/material@0.2.4, npm/@istanbuljs/load-nyc-config@1.0.0, npm/@istanbuljs/schema@0.1.2, npm/@jest/console@24.9.0, npm/@jest/core@24.9.0, npm/@jest/environment@24.9.0, npm/@jest/fake-timers@24.9.0, npm/@jest/globals@25.5.2, npm/@jest/reporters@24.9.0, npm/@jest/source-map@24.9.0, npm/@jest/test-result@24.9.0, npm/@jest/test-sequencer@24.9.0, npm/@jest/transform@24.9.0, npm/@jest/types@24.9.0, npm/@jimp/bmp@0.6.4, npm/@jimp/core@0.22.12, npm/@jimp/custom@0.22.12, npm/@jimp/gif@0.6.4, npm/@jimp/jpeg@0.6.4, npm/@jimp/plugin-blit@0.6.4, npm/@jimp/plugin-blur@0.6.4, npm/@jimp/plugin-color@0.6.4, npm/@jimp/plugin-contain@0.6.4, npm/@jimp/plugin-cover@0.6.4, npm/@jimp/plugin-crop@0.22.12, npm/@jimp/plugin-displace@0.6.4, npm/@jimp/plugin-dither@0.6.4, npm/@jimp/plugin-flip@0.6.4, npm/@jimp/plugin-gaussian@0.6.4, npm/@jimp/plugin-invert@0.6.4, npm/@jimp/plugin-mask@0.6.4, npm/@jimp/plugin-normalize@0.6.4, npm/@jimp/plugin-print@0.6.4, npm/@jimp/plugin-resize@0.22.12, npm/@jimp/plugin-rotate@0.22.12, npm/@jimp/plugin-scale@0.22.12, npm/@jimp/plugins@0.6.4, npm/@jimp/png@0.6.4, npm/@jimp/tiff@0.6.4, npm/@jimp/types@0.6.4, npm/@juggle/resize-observer@2.5.0, npm/@kwsites/file-exists@1.1.1, npm/@kwsites/promise-deferred@1.1.1, npm/@lezer/common@0.15.12, npm/@mikaelkristiansson/domready@1.0.9, npm/@nodelib/fs.stat@2.0.3, npm/@npmcli/move-file@1.0.1, npm/@octokit/request-error@1.0.4, npm/@parcel/fs@1.11.0, npm/@parcel/logger@1.11.1, npm/@parcel/watcher@1.12.1, npm/@pieh/friendly-errors-webpack-plugin@1.7.0-chalk-2, npm/@popmotion/easing@1.0.2, npm/@popmotion/popcorn@0.4.4, npm/@reach/auto-id@0.10.3, npm/@reach/combobox@0.10.3, npm/@reach/menu-button@0.10.3, npm/@reach/observe-rect@1.1.0, npm/@reach/portal@0.10.3, npm/@reach/rect@0.10.3, npm/@reach/router@1.2.1, npm/@reach/skip-nav@0.10.4, npm/@reach/tooltip@0.12.1, npm/@reach/utils@0.10.4, npm/@reach/visually-hidden@0.12.0, npm/@react-hook/hover@1.0.1, npm/@react-hook/mouse-position@1.0.3

View full report↗︎

Copy link

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSource
Install scripts npm/core-js@2.6.9
  • Install script: postinstall
  • Source: node scripts/postinstall || echo "ignore"
Known Malware npm/fsevents@1.2.4
  • Note: This package downloads prebuilt artifacts from a domain which has been compromised. Your system may be infected if you installed this package prior to April 27, 2023
Install scripts npm/fsevents@1.2.4
  • Install script: install
  • Source: node install
Install scripts npm/parcel-bundler@1.9.7
  • Install script: postinstall
  • Source: node -e "console.log('\u001b[35m\u001b[1mLove Parcel? You can now donate to our open collective:\u001b[22m\u001b[39m\n > \u001b[34mhttps://opencollective.com/parcel/donate\u001b[0m')"
Install scripts npm/deasync@0.1.13
  • Install script: install
  • Source: node ./build.js

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

What is known malware?

This package is malware. We have asked the package registry to remove it.

It is strongly recommended that malware is removed from your codebase.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/core-js@2.6.9
  • @SocketSecurity ignore npm/fsevents@1.2.4
  • @SocketSecurity ignore npm/parcel-bundler@1.9.7
  • @SocketSecurity ignore npm/deasync@0.1.13

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants