MetaMask / metamask-docs

Developer documentation for MetaMask
https://docs.metamask.io
Apache License 2.0
636 stars 908 forks source link

feat(siwsrp): add login flow with Profile Sync SDK #1323

Closed cedricmagne closed 1 month ago

cedricmagne commented 1 month ago

Description

Preview link

Checklist

Complete this checklist before merging your PR:

socket-security[bot] commented 1 month ago

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@lavamoat/allow-scripts@3.0.4 environment Transitive: filesystem, network, shell, unsafe +123 7.93 MB boneskull
npm/@metamask/docusaurus-openrpc@0.4.1 Transitive: environment, eval, filesystem, network, shell, unsafe +859 116 MB metamaskbot
npm/@metamask/profile-sync-controller@0.0.0 network Transitive: environment, filesystem +23 24.8 MB metamaskbot
npm/@tanstack/react-query@5.37.1 environment +1 3.02 MB tannerlinsley
npm/viem@1.21.4 network Transitive: environment, filesystem +12 11.5 MB jmoxey
npm/wagmi@2.9.5 Transitive: environment, eval, filesystem, network, shell, unsafe +382 122 MB

🚮 Removed packages: npm/@lavamoat/allow-scripts@2.5.1, npm/@metamask/docusaurus-openrpc@0.4.0

View full report↗︎

socket-security[bot] commented 1 month ago

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSource
Shell access npm/detect-libc@1.0.3
New author npm/use-sync-external-store@1.2.0
Shell access npm/foreground-child@3.1.1
Shell access npm/foreground-child@3.1.1
Network access npm/cross-fetch@3.1.8
Shell access npm/xmlhttprequest-ssl@2.0.0
Network access npm/xmlhttprequest-ssl@2.0.0
Network access npm/xmlhttprequest-ssl@2.0.0
Native code npm/secp256k1@5.0.0
New author npm/abbrev@2.0.0
Network access npm/micro-ftch@0.3.1
Network access npm/micro-ftch@0.3.1
Network access npm/micro-ftch@0.3.1
Network access npm/http-shutdown@1.2.2
Network access npm/http-shutdown@1.2.2
Native code npm/keccak@3.0.4
Network access npm/cross-fetch@4.0.0
New author npm/@walletconnect/environment@1.0.1
New author npm/@walletconnect/safe-json@1.0.2
New author npm/@walletconnect/events@1.0.1
Network access npm/@walletconnect/modal-core@2.6.2
New author npm/@walletconnect/relay-auth@1.0.4
New author npm/@walletconnect/time@1.0.2
New author npm/@walletconnect/window-getters@1.0.1
New author npm/@walletconnect/window-metadata@1.0.1
New author npm/sonic-boom@2.8.0
New author npm/get-stream@8.0.1
Deprecated npm/@motionone/vue@10.16.4
  • Reason: Motion One for Vue is deprecated. Use Oku Motion instead https://oku-ui.com/motion
Native code npm/bufferutil@4.0.8
New author npm/@metamask/eth-json-rpc-provider@1.0.1
New author npm/@metamask/onboarding@1.0.1
New author npm/extension-port-stream@3.0.0
New author npm/is64bit@2.0.0
AI warning npm/untun@0.1.3
  • Notes: The code appears to have risky practices such as downloading and executing binaries without validation and potential code execution via execSync. It does not contain obvious malware, but there is a risk associated with executing downloaded binaries and scripts without proper validation or integrity checks.
  • Confidence: 1.00
  • Severity: 0.60
Network access npm/viem@1.21.4
New author npm/node-addon-api@7.1.0
Network access npm/listhen@1.7.2
New author npm/superstruct@1.0.4
New author npm/@metamask/safe-event-emitter@3.1.1
New author npm/@coinbase/wallet-sdk@3.9.3
Network access npm/@coinbase/wallet-sdk@3.9.3
Network access npm/ofetch@1.3.4
Network access npm/node-fetch-native@1.6.4
Network access npm/node-fetch-native@1.6.4
Network access npm/node-fetch-native@1.6.4
Network access npm/socks-proxy-agent@8.0.3
Network access npm/agent-base@7.1.1
Network access npm/agent-base@7.1.1