Closed unicscode closed 2 years ago
Dependency issues detected. If you merge this pull request, you will not be alerted to the instances of these issues again.
A dependency change in this PR is introducing new install scripts to your install step.
binding.gyp
yarn.lock
packages/api/package.json
install
Contains native code which could be a vector to obscure malicious code, and generally decrease the likelihood of reproducible or reliable installs.
To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@2.4.2
@SocketSecurity ignore
package-name@version
@SocketSecurity ignore foo@1.0.0 bar@2.4.2
@SocketSecurity ignore cpu-features@0.0.4
Powered by socket.dev
Socket Security Report
Dependency issues detected. If you merge this pull request, you will not be alerted to the instances of these issues again.
📜 New install scripts detected
A dependency change in this PR is introducing new install scripts to your install step.
binding.gyp
yarn.lock
,packages/api/package.json
via ssh2-sftp-client@9.0.4, ssh2@1.11.0install
yarn.lock
,packages/api/package.json
via ssh2-sftp-client@9.0.4, ssh2@1.11.0🫣 Native code
Contains native code which could be a vector to obscure malicious code, and generally decrease the likelihood of reproducible or reliable installs.
yarn.lock
,packages/api/package.json
via ssh2-sftp-client@9.0.4, ssh2@1.11.0Socket.dev scan summary
Bot Commands
To ignore an alert, reply with a comment starting with
@SocketSecurity ignore
followed by a space separated list ofpackage-name@version
specifiers. e.g.@SocketSecurity ignore foo@1.0.0 bar@2.4.2
@SocketSecurity ignore cpu-features@0.0.4
Powered by socket.dev