Skip to content

Conversation

@pcarranzav
Copy link
Member

experimental / WIP, take this with a bucketful of salt, might not work, etc

@socket-security
Copy link

socket-security bot commented Sep 29, 2022

Socket Security Report

Dependency issues detected. If you merge this pull request, you will not be alerted to the instances of these issues again.

📜 New install scripts detected

A dependency change in this PR is introducing new install scripts to your install step.

Package Script field Location
classic-level@1.2.0 (added) binding.gyp package.json via @nomicfoundation/ethereumjs-blockchain@6.0.0, level@8.0.0
classic-level@1.2.0 (added) install package.json via @nomicfoundation/ethereumjs-blockchain@6.0.0, level@8.0.0
es5-ext@0.10.62 (upgraded) postinstall package.json
🫣 Native code

Contains native code which could be a vector to obscure malicious code, and generally decrease the likelihood of reproducible or reliable installs.

Package Location
classic-level@1.2.0 (added) package.json via @nomicfoundation/ethereumjs-blockchain@6.0.0, level@8.0.0
😵‍💫 Bin script confusion

This package has multiple bin scripts with the same name. This can cause non-deterministic behavior when installing or could be a sign of a supply chain attack.

Package Bin script Location
@nomicfoundation/ethereumjs-rlp@4.0.0 (added) rlp package.json
rlp@2.2.6 (added) rlp package.json via ethereum-waffle@3.4.4, @ethereum-waffle/provider@3.4.4, ganache-core@2.13.2, ethereumjs-account@3.0.0
rlp@2.2.7 (added) rlp package.json
Socket.dev scan summary
Issue Status
Did you mean? ✅ no new possible package typos
Install scripts ⚠️ 3 new install scripts detected
Telemetry ✅ no new telemetry
Troll package ✅ no new troll packages
Malware ✅ no new malware
Native code ⚠️ 1 new native module detected
Bin Script Confusion ⚠️ 3 new bin script confusions detected
Bin script shell injection ✅ no new bin script shell injection
Bot Commands

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@2.4.2

  • @SocketSecurity ignore classic-level@1.2.0
  • @SocketSecurity ignore es5-ext@0.10.62
  • @SocketSecurity ignore @nomicfoundation/ethereumjs-rlp@4.0.0
  • @SocketSecurity ignore rlp@2.2.6
  • @SocketSecurity ignore rlp@2.2.7

Powered by socket.dev

@codecov
Copy link

codecov bot commented Sep 29, 2022

Codecov Report

Base: 91.56% // Head: 91.54% // Decreases project coverage by -0.02% ⚠️

Coverage data is based on head (fc7120d) compared to base (263355d).
Patch coverage: 88.97% of modified lines in pull request are covered.

Additional details and impacted files
@@                    Coverage Diff                    @@
##           pcv/l2-linear-rewards     #725      +/-   ##
=========================================================
- Coverage                  91.56%   91.54%   -0.03%     
=========================================================
  Files                         42       42              
  Lines                       2003     1998       -5     
  Branches                     350      350              
=========================================================
- Hits                        1834     1829       -5     
  Misses                       169      169              
Flag Coverage Δ
unittests 91.54% <88.97%> (-0.03%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Impacted Files Coverage Δ
contracts/base/Multicall.sol 100.00% <ø> (ø)
contracts/curation/GraphCurationToken.sol 100.00% <ø> (ø)
contracts/discovery/ServiceRegistry.sol 100.00% <ø> (ø)
contracts/discovery/SubgraphNFTDescriptor.sol 100.00% <ø> (ø)
...ontracts/discovery/erc1056/EthereumDIDRegistry.sol 0.00% <ø> (ø)
contracts/gateway/BridgeEscrow.sol 100.00% <ø> (ø)
contracts/gateway/GraphTokenGateway.sol 100.00% <ø> (ø)
contracts/governance/Controller.sol 100.00% <ø> (ø)
contracts/governance/Governed.sol 100.00% <ø> (ø)
contracts/governance/GraphGovernance.sol 100.00% <ø> (ø)
... and 32 more

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

☔ View full report at Codecov.
📢 Do you have feedback about the report comment? Let us know in this issue.

@pcarranzav pcarranzav closed this Dec 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants