OneKeyHQ / app-monorepo

Secure, open source and community driven crypto wallet runs on all platforms and trusted by millions.
https://onekey.so
Other
1.92k stars 362 forks source link

feat: add disableKeyboardAnimation to Page.Footer OK-30043 OK-30070 #5182

Closed hellohublot closed 1 month ago

codesandbox[bot] commented 1 month ago

Review or Edit in CodeSandbox

Open the branch in Web EditorVS CodeInsiders
Open Preview

what-the-diff[bot] commented 1 month ago

PR Summary

socket-security[bot] commented 1 month ago

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@solana/web3.js@1.87.6 environment, eval, network +2 11.4 MB steveluscher
npm/@substrate/txwrapper-polkadot@7.5.1 None 0 63.9 kB bee344
npm/@tamagui/animations-moti@1.79.19 environment 0 38.5 kB nwienert
npm/@tamagui/babel-plugin@1.79.19 environment 0 98.6 kB nwienert
npm/@tamagui/config@1.79.19 None 0 8.38 MB nwienert
npm/@tamagui/static@1.79.19 environment, filesystem, shell, unsafe 0 1.27 MB nwienert
npm/@tamagui/themes@1.79.19 None 0 8.92 MB nwienert
npm/@tamagui/toast@1.79.19 environment 0 945 kB nwienert
npm/@types/chrome@0.0.263 None 0 694 kB types
npm/@types/elliptic@6.4.18 None 0 11.8 kB types
npm/@types/ethjs-util@0.1.3 None 0 4.01 kB types
npm/@types/hdkey@2.0.3 None 0 4.3 kB types
npm/@types/jest@29.5.11 None 0 78.7 kB types
npm/@types/json-schema@7.0.15 None 0 31.7 kB types
npm/@types/lodash@4.14.202 None 0 862 kB types
npm/@types/long@5.0.0 None 0 1.71 kB types
npm/@types/memoizee@0.4.11 None 0 4.38 kB types
npm/@types/punycode@2.1.4 None 0 2.8 kB types
npm/@types/react-dom@18.3.0 None 0 37.8 kB types
npm/@types/react@18.2.45 None 0 365 kB types
npm/@typescript-eslint/eslint-plugin@5.62.0 None 0 2.43 MB jameshenry
npm/@typescript-eslint/parser@5.62.0 None 0 18.6 kB jameshenry
npm/@ungap/structured-clone@1.2.0 None 0 26.2 kB webreflection
npm/@vespaiach/axios-fetch-adapter@0.3.1 network 0 11.3 kB vespaiach
npm/@wagmi/core@2.6.9 None 0 1.61 MB awkweb
npm/@walletconnect/modal@2.6.2 None 0 558 kB iljadoesdev
npm/@walletconnect/universal-provider@2.11.2 eval 0 4.7 MB gancho_walletconnect
npm/@walletconnect/web3wallet@1.10.2 None 0 2.69 MB gancho_walletconnect
npm/ajv@8.12.0 eval 0 1.02 MB esp
npm/ansi-styles@4.3.0 None 0 17 kB sindresorhus
npm/aptos@1.21.0 None 0 6.73 MB aptos-labs
npm/assert@2.1.0 None 0 82.1 kB ljharb
npm/axios@1.6.2 network 0 1.8 MB jasonsaayman
npm/babel-loader@9.1.3 filesystem Transitive: environment +3 294 kB nicolo-ribaudo
npm/babel-plugin-catch-logger@0.1.13 None 0 22.6 kB workboring
npm/babel-plugin-import@1.13.8 None 0 37.5 kB sorrycc
npm/babel-plugin-inline-import@3.0.0 filesystem 0 11.9 kB aldeed
npm/babel-plugin-module-resolver@5.0.0 environment, filesystem 0 25.1 kB tleunen
npm/babel-plugin-react-native-web@0.19.10 None 0 17.2 kB necolas
npm/babel-plugin-transform-define@2.1.4 None 0 13.9 kB formidablelabs
npm/babel-plugin-transform-inline-environment-variables@0.4.4 None 0 3.41 kB nicolo-ribaudo
npm/babel-plugin-transform-remove-console@6.9.4 None 0 3.66 kB boopathi
npm/bech32@2.0.0 None 0 10.2 kB junderw
npm/biginteger@1.0.3 None 0 6.7 MB ashnur
npm/bignumber.js@9.1.2 None 0 351 kB mikemcl
npm/bitcoinforkjs@5.2.0 None 0 0 B
npm/browserify-zlib@0.2.0 None 0 192 kB dignifiedquire
npm/browserslist@4.23.2 environment, filesystem 0 62.9 kB ai
npm/buffer@6.0.3 None 0 91.3 kB feross
npm/chalk@2.4.2 environment 0 26.9 kB sindresorhus
npm/check-disk-space@3.4.0 None 0 20.6 kB alex-d
npm/cheerio@1.0.0-rc.12 None 0 558 kB feedic
npm/convert-source-map@2.0.0 None 0 15.9 kB phated
npm/copy-webpack-plugin@6.4.1 Transitive: filesystem +5 381 kB evilebottnawi
npm/core-js-compat@3.34.0 None 0 695 kB zloirock
npm/cross-env@7.0.3 environment 0 29.1 kB kentcdodds
npm/crypto-browserify@3.12.0 None 0 53.5 kB cwmma
npm/css-loader@6.8.1 None 0 131 kB evilebottnawi
npm/date-fns@2.30.0 None 0 6.69 MB kossnocorp
npm/debug@4.3.4 environment 0 42.4 kB qix
npm/duplicate-package-checker-webpack-plugin@3.0.0 None 0 181 kB darrenscerri
npm/ejs-loader@0.5.0 None 0 10.7 kB difelice
npm/electron-root-path@1.1.0 None 0 8.51 kB ganeshrvel
npm/electron@31.2.0 None 0 993 kB electron-nightly
npm/eslint-config-airbnb-typescript@17.1.0 None 0 26.5 kB iamturns
npm/eslint-config-airbnb@19.0.4 None 0 81.7 kB ljharb
npm/eslint-config-prettier@8.10.0 None 0 19.9 kB lydell
npm/eslint-config-wesbos@3.2.3 None 0 13.9 kB wesbos
npm/eslint-plugin-ban@1.5.2 None 0 15 kB remithomas
npm/eslint-plugin-html@7.1.0 None 0 42.2 kB benoitz
npm/eslint-plugin-import-path@0.0.2 None 0 9.74 kB andrienko
npm/eslint-plugin-import@2.29.1 filesystem, unsafe 0 1.21 MB ljharb
npm/eslint-plugin-jest@27.6.0 filesystem 0 320 kB simenb
npm/eslint-plugin-jsx-a11y@6.8.0 None 0 739 kB ljharb
npm/eslint-plugin-prettier@4.2.1 None 0 58.3 kB jounqin
npm/eslint-plugin-react-hooks@4.6.0 environment 0 118 kB gnoff
npm/eslint-plugin-react@7.33.2 filesystem +3 989 kB ljharb
npm/eslint-plugin-spellcheck@0.0.20 filesystem 0 2.42 MB aotaduy
npm/eslint-plugin-use-effect-no-deps@1.1.2 None 0 6.2 kB alxhenry
npm/eslint@8.56.0 environment, filesystem +3 3.16 MB eslintbot
npm/events@3.3.0 None 0 82.8 kB goto-bus-stop
npm/expiry-map@2.0.0 None 0 6.22 kB samverschueren
npm/expo@50.0.5 environment 0 171 kB brentvatne
npm/fake-indexeddb@5.0.1 None 0 258 kB dumbmatter
npm/fast-glob@3.3.2 filesystem 0 96.7 kB mrmlnc
npm/fast-safe-stringify@2.1.1 None 0 39.7 kB matteo.collina
npm/find-cache-dir@3.3.2 filesystem 0 6.79 kB sindresorhus
npm/find-up@5.0.0 None 0 11.8 kB sindresorhus
npm/find-yarn-workspace-root@2.0.0 filesystem 0 16.7 kB bmishkin
npm/follow-redirects@1.15.3 network 0 28.6 kB rubenverborgh
npm/form-data@4.0.0 filesystem, network 0 43.4 kB niftylettuce
npm/fs-extra@11.2.0 None 0 54.9 kB ryanzim
npm/glob-parent@6.0.2 None 0 7.72 kB phated
npm/html-webpack-plugin@5.6.0 filesystem, unsafe 0 120 kB evilebottnawi
npm/ip@1.1.9 None 0 15.5 kB indutny
npm/is-wsl@2.2.0 environment, filesystem 0 3.76 kB sindresorhus
npm/jayson@4.1.0 network 0 162 kB tedeh
npm/jest-expo@50.0.1 None 0 77.7 kB brentvatne
npm/jest-html-reporter@3.10.2 environment, filesystem 0 29.4 kB hargne
npm/jest@29.7.0 None 0 5.01 kB simenb
npm/jotai@2.6.0 None 0 403 kB daishi
npm/js-tokens@4.0.0 None 0 15.1 kB lydell
npm/jsbi@3.2.5 None 0 322 kB google-wombot
npm/json5@2.2.3 None 0 235 kB jordanbtucker
npm/lightweight-charts@3.8.0 environment 0 1.61 MB timocov
npm/loader-utils@2.0.4 None 0 36.3 kB evilebottnawi
npm/lodash@4.17.21 None 0 1.41 MB bnjmnt4n
npm/long@5.2.3 None 0 119 kB dcode
npm/lru-cache@10.2.0 None 0 458 kB isaacs
npm/make-dir@3.1.0 filesystem 0 10 kB sindresorhus
npm/memoizee@0.4.15 None 0 55.6 kB medikoo
npm/metro@0.80.5 environment, filesystem, network 0 801 kB metro-bot
npm/mipd@0.0.7 None 0 40.8 kB awkweb
npm/mobile-detect@1.4.5 None 0 126 kB hgoebl
npm/ms@2.1.3 None 0 6.72 kB styfle
npm/natsort@2.0.3 None 0 12.7 kB bubkoo
npm/node-notifier@10.0.1 environment, filesystem, network, shell 0 5.68 MB mikaelb
npm/normalize-path@3.0.0 None 0 9.22 kB jonschlinkert
npm/patch-package@7.0.2 environment, filesystem Transitive: shell +1 338 kB ds300
npm/prettier@2.8.8 environment, filesystem, unsafe 0 11.2 MB prettier-bot
npm/progress-bar-webpack-plugin@2.1.0 None +1 38.4 kB clessg
npm/protobufjs@6.11.4 filesystem, network +1 14.8 MB google-wombot
npm/punycode@2.3.1 None 0 33.5 kB google-wombot
npm/react-dev-utils@12.0.1 None 0 111 kB iansu
npm/react-dom@18.2.0 environment 0 4.5 MB gnoff
npm/react-native-ble-manager@8.8.0 None 0 222 kB marcosinigaglia
npm/react-native-cloud-fs@2.6.2 None 0 0 B
npm/react-native-copy-asset@3.0.2 filesystem 0 28.2 kB ridvanaltun
npm/react-native-draggable-flatlist@4.0.1 None 0 523 kB computerjazz
npm/react-native-flipper@0.201.0 None 0 120 kB flipper-bot
npm/react-native-reanimated@3.6.1 environment, eval 0 3.49 MB piaskowyk
npm/react-native-web@0.18.12 environment 0 2.79 MB necolas
npm/react-native-webview-cleaner@1.0.0 None 0 0 B
npm/react-native-webview@13.10.5 None 0 645 kB react-native-community-bot
npm/react-native@0.73.7 environment, network 0 69.7 MB react-native-bot
npm/react-refresh@0.14.0 environment 0 58.7 kB gnoff
npm/react-render-tracker@0.7.6 network 0 1.65 MB lahmatiy
npm/react@18.2.0 environment 0 316 kB gnoff
npm/rimraf@5.0.5 environment, filesystem 0 277 kB isaacs
npm/ripple-keypairs@1.3.1 None 0 38.5 kB khancode_
npm/rpc-websockets@7.9.0 None 0 5.44 MB mkozjak
npm/semver@7.5.4 None 0 93.4 kB npm-cli-ops
npm/serialize-javascript@6.0.1 None 0 16.8 kB okuryu
npm/sha.js@2.4.11 None 0 31.1 kB dcousens
npm/sonner@1.4.41 None 0 447 kB emilkowalski
npm/stream-browserify@3.0.0 None 0 11.6 kB goto-bus-stop
npm/style-loader@3.3.3 None 0 61 kB evilebottnawi
npm/superagent@6.1.0 environment, filesystem, network +1 786 kB niftylettuce
npm/supports-color@7.2.0 None 0 7.04 kB sindresorhus
npm/tamagui-loader@1.79.19 environment +1 102 kB nwienert
npm/tamagui@1.79.19 environment 0 3.66 MB nwienert
npm/tapable@2.2.1 None 0 46.9 kB sokra
npm/terser-webpack-plugin@5.3.9 None +2 297 kB evilebottnawi
npm/ts-jest@29.1.1 environment, filesystem, unsafe 0 307 kB kul
npm/tweetnacl@1.0.3 None 0 175 kB dchest
npm/ultra-runner@3.10.5 environment, filesystem, shell, unsafe 0 251 kB flemaitr
npm/use-suspender@2.0.0-beta.0 None 0 50.2 kB octetstream
npm/uuid@8.3.2 None 0 116 kB ctavan
npm/viem@2.9.2 network Transitive: environment +1 11.3 MB jmoxey
npm/webpack-bundle-analyzer@4.10.1 environment, filesystem, network +1 1.24 MB valscion
npm/webpack-cli@5.1.4 environment, filesystem, unsafe 0 110 kB evilebottnawi
npm/webpack-dev-server@4.15.1 environment, eval, network +3 835 kB evilebottnawi
npm/webpack-manifest-plugin@5.0.0 filesystem +1 95.5 kB shellscape
npm/webpack-subresource-integrity@5.2.0-rc.1 filesystem 0 283 kB jscheid
npm/webpack@5.90.3 environment, filesystem, network, unsafe +3 5.09 MB evilebottnawi
npm/worker-loader@3.0.8 None +2 246 kB evilebottnawi
npm/xlsx@0.19.1 None 0 0 B
npm/yallist@3.1.1 None 0 14.8 kB isaacs

🚮 Removed packages: npm/7zip-bin@5.2.0, npm/@0no-co/graphql.web@1.0.4, npm/@babel/plugin-proposal-class-properties@7.18.6, npm/@babel/plugin-proposal-nullish-coalescing-operator@7.18.6, npm/@babel/plugin-proposal-object-rest-spread@7.20.7, npm/@babel/plugin-proposal-optional-chaining@7.21.0, npm/@babel/plugin-syntax-export-default-from@7.23.3, npm/@babel/plugin-syntax-flow@7.23.3, npm/@babel/plugin-syntax-jsx@7.23.3, npm/@babel/plugin-syntax-typescript@7.23.3, npm/@babel/plugin-transform-flow-strip-types@7.23.3, npm/@babel/plugin-transform-react-display-name@7.23.3, npm/@babel/plugin-transform-react-jsx@7.23.4, npm/@babel/plugin-transform-typescript@7.23.6, npm/@babel/preset-react@7.23.3, npm/@babel/preset-typescript@7.23.3, npm/@babel/runtime@7.23.6, npm/@backpackapp-io/react-native-toast@0.10.0, npm/@bitcoinerlab/secp256k1@1.0.5, npm/@bufbuild/protobuf@1.9.0, npm/@bufgix/react-native-secure-window@0.1.1, npm/@bundlr-network/client@0.7.17, npm/@ckb-lumos/base@0.23.0, npm/@ckb-lumos/ckb-indexer@0.23.0, npm/@ckb-lumos/common-scripts@0.23.0, npm/@conflux-dev/conflux-address-js@1.3.16, npm/@develar/schema-utils@2.6.5, npm/@discoveryjs/json-ext@0.5.7, npm/@electron/asar@3.2.8, npm/@electron/notarize@2.2.1, npm/@electron/notarize@2.3.2, npm/@electron/osx-sign@1.0.5, npm/@electron/remote@2.1.1, npm/@electron/universal@1.5.1, npm/@emotion/is-prop-valid@0.8.8, npm/@emotion/memoize@0.7.4, npm/@emotion/unitless@0.8.0, npm/@emurgo/cardano-message-signing-asmjs@1.0.1, npm/@emurgo/cardano-message-signing-browser@1.0.1, npm/@emurgo/cardano-serialization-lib-asmjs@11.1.0, npm/@emurgo/cardano-serialization-lib-browser@11.1.0, npm/@esbuild/android-arm@0.19.10, npm/@esbuild/linux-loong64@0.19.10, npm/@eslint-community/regexpp@4.10.0, npm/@ethereumjs/common@2.6.5, npm/@ethereumjs/util@8.1.0, npm/@ethersproject/abi@5.7.0, npm/@ethersproject/abstract-provider@5.7.0, npm/@ethersproject/abstract-signer@5.7.0, npm/@ethersproject/address@5.7.0, npm/@ethersproject/base64@5.7.0, npm/@ethersproject/basex@5.7.0, npm/@ethersproject/bignumber@5.7.0, npm/@ethersproject/bytes@5.7.0, npm/@ethersproject/constants@5.7.0, npm/@ethersproject/hash@5.7.0, npm/@ethersproject/hdnode@5.7.0, npm/@ethersproject/json-wallets@5.7.0, npm/@ethersproject/keccak256@5.7.0, npm/@ethersproject/logger@5.7.0, npm/@ethersproject/networks@5.7.1, npm/@ethersproject/pbkdf2@5.7.0, npm/@ethersproject/properties@5.7.0, npm/@ethersproject/providers@5.7.2, npm/@ethersproject/random@5.7.0, npm/@ethersproject/rlp@5.7.0, npm/@ethersproject/sha2@5.7.0, npm/@ethersproject/signing-key@5.7.0, npm/@ethersproject/strings@5.7.0, npm/@ethersproject/transactions@5.7.0, npm/@ethersproject/web@5.7.1, npm/@ethersproject/wordlists@5.7.0, npm/@expo/config-plugins@7.8.4, npm/@expo/config-types@50.0.0, npm/@expo/config@8.5.4, npm/@expo/json-file@8.3.0, npm/@expo/metro-config@0.17.3, npm/@expo/plist@0.1.0, npm/@expo/spawn-async@1.5.0, npm/@findeth/abi@0.3.1, npm/@floating-ui/core@1.5.2, npm/@formatjs/ecma402-abstract@1.11.4, npm/@formatjs/fast-memoize@2.2.0, npm/@formatjs/icu-messageformat-parser@2.7.8, npm/@formatjs/intl-displaynames@6.6.8, npm/@formatjs/intl-getcanonicallocales@1.9.2, npm/@formatjs/intl-listformat@7.5.7, npm/@formatjs/intl-locale@2.4.47, npm/@formatjs/intl-pluralrules@4.3.3, npm/@formatjs/intl@2.10.4, npm/@glif/filecoin-address@2.0.43, npm/@glif/filecoin-message@2.0.44, npm/@hapi/hoek@9.3.0, npm/@hapi/topo@5.1.0, npm/@ide/backoff@1.0.0, npm/@ipld/dag-cbor@9.0.6, npm/@jest/create-cache-key-function@29.7.0, npm/@jest/test-result@29.7.0, npm/@jest/types@29.6.3, npm/@kaspa/core-lib@1.6.5, npm/@keystonehq/bc-ur-registry-aptos@0.3.2, npm/@keystonehq/bc-ur-registry-arweave@0.4.0, npm/@keystonehq/bc-ur-registry-btc@0.1.0, npm/@keystonehq/bc-ur-registry-cardano@0.3.0, npm/@keystonehq/bc-ur-registry-cosmos@0.2.2, npm/@keystonehq/bc-ur-registry-eth@0.15.2, npm/@keystonehq/bc-ur-registry-evm@0.5.2, npm/@keystonehq/bc-ur-registry-keystone@0.1.0, npm/@keystonehq/bc-ur-registry-near@0.8.0, npm/@keystonehq/bc-ur-registry-sol@0.6.2, npm/@keystonehq/bc-ur-registry-sui@0.3.0, npm/@keystonehq/bc-ur-registry-ton@0.1.0, npm/@keystonehq/bc-ur-registry@0.5.4, npm/@keystonehq/keystone-sdk@0.4.1, npm/@koale/useworker@4.0.2, npm/@lit-labs/ssr-dom-shim@1.2.0, npm/@lit/reactive-element@1.6.3, npm/@magiceden-oss/open_creator_protocol@0.3.5, npm/@malept/flatpak-bundler@0.4.0, npm/@metamask/eth-sig-util@5.1.0, npm/@metaplex-foundation/beet-solana@0.3.1, npm/@metaplex-foundation/beet@0.7.2, npm/@metaplex-foundation/mpl-token-metadata@2.13.0, npm/@metaplex-foundation/rustbin@0.3.5, npm/@motionone/animation@10.16.3, npm/@motionone/types@10.16.3, npm/@motionone/utils@10.16.3, npm/@mymonero/mymonero-app-bridge@3.0.0, npm/@mymonero/mymonero-keyimage-cache@3.0.0, npm/@near-js/accounts@0.1.4, npm/@near-js/keystores-browser@0.0.5, npm/@near-js/keystores-node@0.0.5, npm/@near-js/wallet-account@0.0.7, npm/@noble/ed25519@1.7.3, npm/@nodelib/fs.stat@2.0.5, npm/@nodelib/fs.walk@1.2.8, npm/@onekeyfe/cardano-coin-selection-asmjs@1.1.0, npm/@onekeyfe/cardano-coin-selection@1.0.0, npm/@onekeyfe/react-native-animated-charts@1.0.0, npm/@onekeyfe/react-native-cloud-fs@2.6.1, npm/@onekeyfe/react-native-lite-card@1.0.7, npm/@onekeyfe/react-native-tab-page-view@1.0.5, npm/@onekeyfe/react-native-webview-cleaner@1.0.0, npm/@onekeyfe/react-native-webview@13.8.2, npm/@polkadot-api/json-rpc-provider-proxy@0.0.1-492c132563ea6b40ae1fc5470dec4cd18768d182.1.0, npm/@polkadot-api/json-rpc-provider@0.0.1-492c132563ea6b40ae1fc5470dec4cd18768d182.1.0, npm/@polkadot-api/metadata-builders@0.0.1-492c132563ea6b40ae1fc5470dec4cd18768d182.1.0, npm/@polkadot-api/substrate-bindings@0.0.1-492c132563ea6b40ae1fc5470dec4cd18768d182.1.0, npm/@polkadot-api/substrate-client@0.0.1-492c132563ea6b40ae1fc5470dec4cd18768d182.1.0, npm/@polkadot-api/utils@0.0.1-492c132563ea6b40ae1fc5470dec4cd18768d182.1.0, npm/@polkadot/api-augment@10.11.2, npm/@polkadot/api-base@10.11.2, npm/@polkadot/api-derive@10.11.2, npm/@polkadot/api@10.11.2, npm/@polkadot/networks@12.6.2, npm/@polkadot/rpc-augment@10.11.2, npm/@polkadot/rpc-core@10.11.2, npm/@polkadot/rpc-provider@10.13.1, npm/@polkadot/types-known@10.11.2, npm/@polkadot/util@12.6.2, npm/@polkadot/wasm-util@7.3.2, npm/@polkadot/x-bigint@12.6.2, npm/@polkadot/x-global@12.6.2, npm/@project-serum/borsh@0.2.5, npm/@protobufjs/aspromise@1.1.2, npm/@react-native-async-storage/async-storage@1.22.0, npm/@react-native-community/cli-clean@12.3.6, npm/@react-native-community/cli-config@12.3.6, npm/@react-native-community/cli-debugger-ui@12.3.6, npm/@react-native-community/cli-doctor@12.3.6, npm/@react-native-community/cli-hermes@12.3.6, npm/@react-native-community/cli-platform-android@12.3.6, npm/@react-native-community/cli-platform-apple@13.6.6, npm/@react-native-community/cli-platform-ios@12.3.6, npm/@react-native-community/cli-server-api@12.3.6, npm/@react-native-community/cli-types@12.3.6, npm/@react-native-community/cli@12.3.6, npm/@react-native-community/netinfo@9.5.0, npm/@react-native-community/slider@4.4.3, npm/@react-native-firebase/app@20.1.0, npm/@react-native-firebase/crashlytics@20.1.0, npm/@react-native-google-signin/google-signin@9.1.0, npm/@react-native/assets-registry@0.73.1, npm/@react-native/babel-plugin-codegen@0.74.85, npm/@react-native/babel-preset@0.74.85, npm/@react-native/codegen@0.74.85, npm/@react-native/community-cli-plugin@0.73.17, npm/@react-native/debugger-frontend@0.73.3, npm/@react-native/dev-middleware@0.73.7, npm/@react-native/gradle-plugin@0.73.4, npm/@react-native/js-polyfills@0.73.1, npm/@react-native/metro-babel-transformer@0.73.15, npm/@react-native/normalize-color@2.1.0, npm/@react-native/normalize-colors@0.73.2, npm/@react-native/virtualized-lists@0.73.4, npm/@react-navigation/bottom-tabs@6.5.9, npm/@react-navigation/core@6.4.16, npm/@react-navigation/devtools@6.0.20, npm/@react-navigation/drawer@6.6.4, npm/@react-navigation/elements@1.3.21, npm/@react-navigation/native-stack@6.9.14, npm/@react-navigation/native@6.1.17, npm/@react-navigation/stack@6.3.20, npm/@reduxjs/toolkit@1.9.7, npm/@rnx-kit/chromium-edge-launcher@1.0.0, npm/@scure/base@1.1.5, npm/@shopify/flash-list@1.6.3, npm/@sideway/address@4.1.4, npm/@sindresorhus/is@4.6.0, npm/@socket.io/component-emitter@3.1.0, npm/@solana/buffer-layout@4.0.1, npm/@solana/spl-token@0.3.11, npm/@walletconnect/react-native-compat@2.11.2, npm/electron@27.0.0, npm/esbuild@0.15.18, npm/expo-haptics@12.6.0, npm/expo-screen-capture@5.8.1, npm/react-native-ble-manager@10.1.5, npm/react-native-gesture-handler@2.14.1, npm/react-native-get-random-values@1.9.0, npm/react-native-safe-area-context@4.7.2, npm/react-native-screens@3.28.0, npm/realm@12.3.0, npm/rimraf@3.0.2

View full report↗︎

socket-security[bot] commented 1 month ago

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSourceCI
Install scripts npm/protobufjs@6.11.4
  • Install script: postinstall
  • Source: node scripts/postinstall
🚫
Install scripts npm/web3@1.10.3
  • Install script: postinstall
  • Source: echo "Web3.js 4.x alpha has been released for early testing and feedback. Checkout doc at https://docs.web3js.org/ "
🚫
Potential typo squat npm/biginteger@1.0.3 🚫

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

What is a typosquat?

Package name is similar to other popular packages and may not be the package you want.

Use care when consuming similarly named packages and ensure that you did not intend to consume a different package. Malicious packages often publish using similar names as existing popular packages.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/protobufjs@6.11.4
  • @SocketSecurity ignore npm/web3@1.10.3
  • @SocketSecurity ignore npm/biginteger@1.0.3