Closed Mrtenz closed 1 year ago
New dependency changes detected. Learn more about Socket for GitHub ↗︎
👍 No new dependency issues detected in pull request
To ignore an alert, reply with a comment starting with @SocketSecurity ignore
followed by a space separated list of package-name@version
specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@*
or ignore all packages with @SocketSecurity ignore-all
Ignoring: @lavamoat/preinstall-always-fail@1.0.0
Issue | Status |
---|---|
Install scripts | ✅ 0 issues |
Native code | ✅ 0 issues |
Bin script shell injection | ✅ 0 issues |
Unresolved require | ✅ 0 issues |
Invalid package.json | ✅ 0 issues |
HTTP dependency | ✅ 0 issues |
Git dependency | ✅ 0 issues |
Potential typo squat | ✅ 0 issues |
Known Malware | ✅ 0 issues |
Telemetry | ✅ 0 issues |
Protestware/Troll package | ✅ 0 issues |
📊 Modified Dependency Overview:
➕ Added Package | Capability Access | +/- Transitive Count |
Publisher |
---|---|---|---|
@lavamoat/preinstall-always-fail@1.0.0 | None | +0 |
kumavis |
@SocketSecurity ignore @lavamoat/preinstall-always-fail@1.0.0
Description
This pull request adds the
@lavamoat/preinstall-always-fail
to thedevDependencies
of the project. The package was previously specified in thelavamoat
configuration section, but not installed. This made the specified configuration of no effect.Additionally, the package has been added to
.depcheckrc.json
file, which is a configuration file for detecting missing dependencies in our codebase. This was done to prevent any warnings or errors related to this package from being raised.Changes
@lavamoat/preinstall-always-fail
todevDependencies
.@lavamoat/preinstall-always-fail
to.depcheckrc.json
.