SocialGouv / kontinuous

Kontinuous - GitOps for Kubernetes 🥷
https://socialgouv.github.io/kontinuous/
MIT License
11 stars 0 forks source link

chore(deps): update dependency tar to v6.2.1 [security] - autoclosed #471

Closed renovate[bot] closed 5 months ago

renovate[bot] commented 6 months ago

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
tar 6.1.13 -> 6.2.1 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-28863

Description:

During some analysis today on npm's node-tar package I came across the folder creation process, Basicly if you provide node-tar with a path like this ./a/b/c/foo.txt it would create every folder and sub-folder here a, b and c until it reaches the last folder to create foo.txt, In-this case I noticed that there's no validation at all on the amount of folders being created, that said we're actually able to CPU and memory consume the system running node-tar and even crash the nodejs client within few seconds of running it using a path with too many sub-folders inside

Steps To Reproduce:

You can reproduce this issue by downloading the tar file I provided in the resources and using node-tar to extract it, you should get the same behavior as the video

Proof Of Concept:

Here's a video show-casing the exploit:

Impact

Denial of service by crashing the nodejs client when attempting to parse a tar archive, make it run out of heap memory and consuming server CPU and memory resources

Report resources

payload.txt archeive.tar.gz

Note

This report was originally reported to GitHub bug bounty program, they asked me to report it to you a month ago


Release Notes

isaacs/node-tar (tar) ### [`v6.2.1`](https://togithub.com/isaacs/node-tar/compare/v6.2.0...v6.2.1) [Compare Source](https://togithub.com/isaacs/node-tar/compare/v6.2.0...v6.2.1) ### [`v6.2.0`](https://togithub.com/isaacs/node-tar/compare/v6.1.15...v6.2.0) [Compare Source](https://togithub.com/isaacs/node-tar/compare/v6.1.15...v6.2.0) ### [`v6.1.15`](https://togithub.com/isaacs/node-tar/compare/v6.1.14...v6.1.15) [Compare Source](https://togithub.com/isaacs/node-tar/compare/v6.1.14...v6.1.15) ### [`v6.1.14`](https://togithub.com/isaacs/node-tar/compare/v6.1.13...v6.1.14) [Compare Source](https://togithub.com/isaacs/node-tar/compare/v6.1.13...v6.1.14)

Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Paris, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.

sonarcloud[bot] commented 6 months ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarCloud

socket-security[bot] commented 6 months ago

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@ampproject/remapping@2.2.0 None 0 55.3 kB jridgewell
npm/@apidevtools/json-schema-ref-parser@9.0.9 filesystem, network 0 151 kB jamesmessinger
npm/@arcanis/slice-ansi@1.1.1 None 0 5.5 kB arcanis
npm/@aws-crypto/crc32@3.0.0 None 0 32.6 kB aws-crypto-tools-ci-bot
npm/@aws-crypto/crc32c@3.0.0 None 0 30.5 kB aws-crypto-tools-ci-bot
npm/@aws-crypto/ie11-detection@3.0.0 None 0 28.6 kB aws-crypto-tools-ci-bot
npm/@aws-crypto/sha1-browser@3.0.0 None 0 37.9 kB aws-crypto-tools-ci-bot
npm/@aws-crypto/sha256-browser@3.0.0 None 0 42.6 kB aws-crypto-tools-ci-bot
npm/@aws-crypto/sha256-js@3.0.0 None 0 87.4 kB aws-crypto-tools-ci-bot
npm/@aws-crypto/supports-web-crypto@3.0.0 None 0 26 kB aws-crypto-tools-ci-bot
npm/@aws-crypto/util@3.0.0 None 0 24.3 kB aws-crypto-tools-ci-bot
npm/@aws-sdk/abort-controller@3.347.0 None +1 101 kB aws-sdk-bot
npm/@aws-sdk/chunked-blob-reader-native@3.208.0 None +3 87.4 kB aws-sdk-bot
npm/@aws-sdk/chunked-blob-reader@3.310.0 None 0 15.3 kB aws-sdk-bot
npm/@aws-sdk/client-iam@3.282.0 Transitive: environment, filesystem, network, shell +54 6.92 MB aws-sdk-bot
npm/@aws-sdk/client-sso-oidc@3.348.0 None +2 418 kB aws-sdk-bot
npm/@aws-sdk/client-sso@3.348.0 None +2 408 kB aws-sdk-bot
npm/@aws-sdk/client-sts@3.348.0 None +2 659 kB aws-sdk-bot
npm/@aws-sdk/config-resolver@3.347.0 None 0 49.5 kB aws-sdk-bot
npm/@aws-sdk/credential-provider-env@3.347.0 environment 0 16.9 kB aws-sdk-bot
npm/@aws-sdk/credential-provider-imds@3.347.0 environment, network 0 54.4 kB aws-sdk-bot
npm/@aws-sdk/credential-provider-ini@3.348.0 None 0 40 kB aws-sdk-bot
npm/@aws-sdk/credential-provider-node@3.348.0 environment 0 27 kB aws-sdk-bot
npm/@aws-sdk/credential-provider-process@3.347.0 shell 0 22.1 kB aws-sdk-bot
npm/@aws-sdk/credential-provider-sso@3.348.0 None 0 32.1 kB aws-sdk-bot
npm/@aws-sdk/credential-provider-web-identity@3.347.0 environment, filesystem 0 28.9 kB aws-sdk-bot
npm/@aws-sdk/eventstream-codec@3.347.0 None 0 69.7 kB aws-sdk-bot
npm/@aws-sdk/eventstream-serde-browser@3.347.0 None 0 22.5 kB aws-sdk-bot
npm/@aws-sdk/eventstream-serde-config-resolver@3.347.0 None 0 15.4 kB aws-sdk-bot
npm/@aws-sdk/eventstream-serde-node@3.347.0 None 0 20.2 kB aws-sdk-bot
npm/@aws-sdk/eventstream-serde-universal@3.347.0 None 0 36.8 kB aws-sdk-bot
npm/@aws-sdk/fetch-http-handler@3.347.0 network 0 27.6 kB aws-sdk-bot
npm/@aws-sdk/hash-blob-browser@3.347.0 None 0 14.4 kB aws-sdk-bot
npm/@aws-sdk/hash-node@3.347.0 None 0 16.6 kB aws-sdk-bot
npm/@aws-sdk/hash-stream-node@3.347.0 filesystem 0 20.1 kB aws-sdk-bot
npm/@aws-sdk/invalid-dependency@3.347.0 None 0 14.8 kB aws-sdk-bot
npm/@aws-sdk/is-array-buffer@3.310.0 None 0 14 kB aws-sdk-bot
npm/@aws-sdk/md5-js@3.347.0 None 0 31.1 kB aws-sdk-bot
npm/@aws-sdk/middleware-bucket-endpoint@3.347.0 None 0 70.9 kB aws-sdk-bot
npm/@aws-sdk/middleware-content-length@3.347.0 None 0 17.2 kB aws-sdk-bot
npm/@aws-sdk/middleware-endpoint@3.347.0 None 0 44.9 kB aws-sdk-bot
npm/@aws-sdk/middleware-expect-continue@3.347.0 None 0 16.4 kB aws-sdk-bot
npm/@aws-sdk/middleware-flexible-checksums@3.347.0 None 0 45.8 kB aws-sdk-bot
npm/@aws-sdk/middleware-host-header@3.347.0 None 0 17.8 kB aws-sdk-bot
npm/@aws-sdk/middleware-location-constraint@3.347.0 None 0 18.3 kB aws-sdk-bot
npm/@aws-sdk/middleware-logger@3.347.0 None 0 18.9 kB aws-sdk-bot
npm/@aws-sdk/middleware-recursion-detection@3.347.0 environment 0 17.6 kB aws-sdk-bot
npm/@aws-sdk/middleware-retry@3.347.0 None 0 59.7 kB aws-sdk-bot
npm/@aws-sdk/middleware-sdk-ec2@3.347.0 None 0 24.6 kB aws-sdk-bot
npm/@aws-sdk/middleware-sdk-rds@3.347.0 None 0 25.2 kB aws-sdk-bot
npm/@aws-sdk/middleware-sdk-s3@3.347.0 None 0 28 kB aws-sdk-bot
npm/@aws-sdk/middleware-sdk-sts@3.347.0 None 0 16.5 kB aws-sdk-bot
npm/@aws-sdk/middleware-serde@3.347.0 None 0 21.5 kB aws-sdk-bot
npm/@aws-sdk/middleware-signing@3.347.0 None 0 37.6 kB aws-sdk-bot
npm/@aws-sdk/middleware-ssec@3.347.0 None 0 17.8 kB aws-sdk-bot
npm/@aws-sdk/middleware-stack@3.347.0 None 0 37.1 kB aws-sdk-bot
npm/@aws-sdk/middleware-user-agent@3.347.0 None 0 25.5 kB aws-sdk-bot
npm/@aws-sdk/node-config-provider@3.347.0 environment 0 22.9 kB aws-sdk-bot
npm/@aws-sdk/node-http-handler@3.348.0 network 0 77.3 kB aws-sdk-bot
npm/@aws-sdk/property-provider@3.347.0 None 0 27.3 kB aws-sdk-bot
npm/@aws-sdk/protocol-http@3.347.0 None 0 29 kB aws-sdk-bot
npm/@aws-sdk/querystring-builder@3.347.0 None 0 15.2 kB aws-sdk-bot
npm/@aws-sdk/querystring-parser@3.347.0 None 0 15.2 kB aws-sdk-bot
npm/@aws-sdk/service-error-classification@3.347.0 None 0 20.3 kB aws-sdk-bot
npm/@aws-sdk/shared-ini-file-loader@3.347.0 environment, filesystem 0 39.9 kB aws-sdk-bot
npm/@aws-sdk/signature-v4-multi-region@3.347.0 None 0 21.6 kB aws-sdk-bot
npm/@aws-sdk/signature-v4@3.347.0 None 0 104 kB aws-sdk-bot
npm/@aws-sdk/smithy-client@3.347.0 None 0 117 kB aws-sdk-bot
npm/@aws-sdk/token-providers@3.348.0 filesystem 0 34.5 kB aws-sdk-bot
npm/@aws-sdk/types@3.347.0 None 0 118 kB aws-sdk-bot
npm/@aws-sdk/url-parser@3.347.0 None 0 14.6 kB aws-sdk-bot
npm/@aws-sdk/util-arn-parser@3.310.0 None 0 16.2 kB aws-sdk-bot
npm/@aws-sdk/util-base64@3.310.0 None 0 24.7 kB aws-sdk-bot
npm/@aws-sdk/util-body-length-browser@3.310.0 None 0 15.4 kB aws-sdk-bot
npm/@aws-sdk/util-body-length-node@3.310.0 filesystem 0 15.4 kB aws-sdk-bot
npm/@aws-sdk/util-buffer-from@3.310.0 None 0 15.7 kB aws-sdk-bot
npm/@aws-sdk/util-config-provider@3.310.0 None 0 15.4 kB aws-sdk-bot
npm/@aws-sdk/util-defaults-mode-browser@3.347.0 None 0 21.6 kB aws-sdk-bot
npm/@aws-sdk/util-defaults-mode-node@3.347.0 environment 0 23.3 kB aws-sdk-bot
npm/@aws-sdk/util-endpoints@3.347.0 None 0 94.9 kB aws-sdk-bot
npm/@aws-sdk/util-format-url@3.347.0 None 0 15.7 kB aws-sdk-bot
npm/@aws-sdk/util-hex-encoding@3.310.0 None 0 16 kB aws-sdk-bot
npm/@aws-sdk/util-locate-window@3.535.0 None 0 15.1 kB aws-sdk-bot
npm/@aws-sdk/util-middleware@3.347.0 None 0 14.7 kB aws-sdk-bot
npm/@aws-sdk/util-retry@3.347.0 None 0 52.7 kB aws-sdk-bot
npm/@aws-sdk/util-stream-browser@3.347.0 None 0 18.4 kB aws-sdk-bot
npm/@aws-sdk/util-stream-node@3.348.0 None 0 21.8 kB aws-sdk-bot
npm/@aws-sdk/util-uri-escape@3.310.0 None 0 14.8 kB aws-sdk-bot
npm/@aws-sdk/util-user-agent-browser@3.347.0 None 0 18 kB aws-sdk-bot
npm/@aws-sdk/util-user-agent-node@3.347.0 None 0 18.5 kB aws-sdk-bot
npm/@aws-sdk/util-utf8-browser@3.259.0 None 0 20 kB aws-sdk-bot
npm/@aws-sdk/util-utf8@3.310.0 None 0 17.2 kB aws-sdk-bot
npm/@aws-sdk/util-waiter@3.347.0 None 0 27.9 kB aws-sdk-bot
npm/@aws-sdk/xml-builder@3.310.0 None 0 20.7 kB aws-sdk-bot
npm/@babel/compat-data@7.21.0 None 0 57.9 kB nicolo-ribaudo
npm/@babel/core@7.21.0 environment, filesystem, unsafe +1 1.01 MB nicolo-ribaudo
npm/@babel/generator@7.24.4 None +1 574 kB nicolo-ribaudo
npm/@babel/helper-annotate-as-pure@7.18.6 None 0 2.69 kB nicolo-ribaudo
npm/@babel/helper-builder-binary-assignment-operator-visitor@7.18.9 None 0 3.43 kB nicolo-ribaudo
npm/@babel/helper-compilation-targets@7.23.6 None +1 117 kB nicolo-ribaudo
npm/@babel/helper-create-class-features-plugin@7.21.0 None 0 186 kB nicolo-ribaudo
npm/@babel/helper-create-regexp-features-plugin@7.21.0 None 0 26.2 kB nicolo-ribaudo
npm/@babel/helper-define-polyfill-provider@0.3.3 unsafe 0 197 kB nicolo-ribaudo
npm/@babel/helper-explode-assignable-expression@7.18.6 None 0 4.33 kB nicolo-ribaudo
npm/@babel/helper-function-name@7.23.0 None 0 21.6 kB nicolo-ribaudo
npm/@babel/helper-hoist-variables@7.22.5 None 0 7.03 kB nicolo-ribaudo
npm/@babel/helper-member-expression-to-functions@7.23.0 None 0 55 kB nicolo-ribaudo
npm/@babel/helper-module-imports@7.24.3 None 0 63.8 kB nicolo-ribaudo
npm/@babel/helper-module-transforms@7.23.3 None 0 158 kB nicolo-ribaudo
npm/@babel/helper-optimise-call-expression@7.22.5 None 0 6.66 kB nicolo-ribaudo
npm/@babel/helper-remap-async-to-generator@7.18.9 None 0 4.54 kB nicolo-ribaudo
npm/@babel/helper-replace-supers@7.24.1 None 0 32.2 kB nicolo-ribaudo
npm/@babel/helper-simple-access@7.22.5 None 0 14.1 kB nicolo-ribaudo
npm/@babel/helper-skip-transparent-expression-wrappers@7.22.5 None 0 5.96 kB nicolo-ribaudo
npm/@babel/helper-split-export-declaration@7.22.6 None 0 10.7 kB nicolo-ribaudo
npm/@babel/helper-wrap-function@7.22.20 None 0 15.4 kB nicolo-ribaudo
npm/@babel/helpers@7.24.4 None 0 650 kB nicolo-ribaudo
npm/@babel/plugin-bugfix-safari-id-destructuring-collision-in-function-expression@7.18.6 None 0 7.75 kB nicolo-ribaudo
npm/@babel/plugin-bugfix-v8-spread-parameters-in-optional-chaining@7.20.7 None 0 10.5 kB nicolo-ribaudo
npm/@babel/plugin-proposal-async-generator-functions@7.20.7 None 0 20 kB nicolo-ribaudo
npm/@babel/plugin-proposal-class-properties@7.18.6 None 0 3.34 kB nicolo-ribaudo
npm/@babel/plugin-proposal-class-static-block@7.21.0 None 0 9.86 kB nicolo-ribaudo
npm/@babel/plugin-proposal-dynamic-import@7.18.6 None 0 3.67 kB nicolo-ribaudo
npm/@babel/plugin-proposal-export-namespace-from@7.18.9 None 0 4.24 kB nicolo-ribaudo
npm/@babel/plugin-proposal-json-strings@7.18.6 None 0 3.44 kB nicolo-ribaudo
npm/@babel/plugin-proposal-logical-assignment-operators@7.20.7 None 0 8.49 kB nicolo-ribaudo
npm/@babel/plugin-proposal-nullish-coalescing-operator@7.18.6 None 0 4.41 kB nicolo-ribaudo
npm/@babel/plugin-proposal-numeric-separator@7.18.6 None 0 3.37 kB nicolo-ribaudo
npm/@babel/plugin-proposal-object-rest-spread@7.20.7 None 0 70.5 kB nicolo-ribaudo
npm/@babel/plugin-proposal-optional-catch-binding@7.18.6 None 0 3.23 kB nicolo-ribaudo
npm/@babel/plugin-proposal-optional-chaining@7.21.0 None 0 33.2 kB nicolo-ribaudo
npm/@babel/plugin-proposal-private-methods@7.18.6 None 0 3.17 kB nicolo-ribaudo
npm/@babel/plugin-proposal-private-property-in-object@7.21.0 None 0 19.5 kB nicolo-ribaudo
npm/@babel/plugin-proposal-unicode-property-regex@7.18.6 None 0 3.48 kB nicolo-ribaudo
npm/@babel/plugin-syntax-async-generators@7.8.4 None 0 2.52 kB nicolo-ribaudo
npm/@babel/plugin-syntax-bigint@7.8.3 None 0 2.42 kB nicolo-ribaudo
npm/@babel/plugin-syntax-class-properties@7.12.13 None 0 2.68 kB nicolo-ribaudo
npm/@babel/plugin-syntax-class-static-block@7.14.5 None 0 2.74 kB nicolo-ribaudo
npm/@babel/plugin-syntax-dynamic-import@7.8.3 None 0 2.47 kB nicolo-ribaudo
npm/@babel/plugin-syntax-export-namespace-from@7.8.3 None 0 2.62 kB nicolo-ribaudo
npm/@babel/plugin-syntax-import-assertions@7.20.0 None 0 3.5 kB nicolo-ribaudo
npm/@babel/plugin-syntax-import-meta@7.10.4 None 0 2.56 kB jlhwung
npm/@babel/plugin-syntax-json-strings@7.8.3 None 0 2.58 kB nicolo-ribaudo
npm/@babel/plugin-syntax-jsx@7.18.6 None 0 2.74 kB nicolo-ribaudo
npm/@babel/plugin-syntax-logical-assignment-operators@7.10.4 None 0 2.74 kB jlhwung
npm/@babel/plugin-syntax-nullish-coalescing-operator@7.8.3 None 0 2.63 kB nicolo-ribaudo
npm/@babel/plugin-syntax-numeric-separator@7.10.4 None 0 2.75 kB jlhwung
npm/@babel/plugin-syntax-object-rest-spread@7.8.3 None 0 2.53 kB nicolo-ribaudo
npm/@babel/plugin-syntax-optional-catch-binding@7.8.3 None 0 2.57 kB nicolo-ribaudo
npm/@babel/plugin-syntax-optional-chaining@7.8.3 None 0 2.52 kB nicolo-ribaudo
npm/@babel/plugin-syntax-private-property-in-object@7.14.5 None 0 2.82 kB nicolo-ribaudo
npm/@babel/plugin-syntax-top-level-await@7.14.5 None 0 2.74 kB nicolo-ribaudo
npm/@babel/plugin-syntax-typescript@7.20.0 None 0 6.26 kB nicolo-ribaudo
npm/@babel/plugin-transform-arrow-functions@7.20.7 None 0 5.06 kB nicolo-ribaudo
npm/@babel/plugin-transform-async-to-generator@7.20.7 None 0 7.61 kB nicolo-ribaudo
npm/@babel/plugin-transform-block-scoped-functions@7.18.6 None 0 3.73 kB nicolo-ribaudo
npm/@babel/plugin-transform-block-scoping@7.21.0 None 0 83.6 kB nicolo-ribaudo
npm/@babel/plugin-transform-classes@7.21.0 None +1 124 kB nicolo-ribaudo
npm/@babel/plugin-transform-computed-properties@7.20.7 None 0 21.6 kB nicolo-ribaudo
npm/@babel/plugin-transform-destructuring@7.20.7 None 0 81.5 kB nicolo-ribaudo
npm/@babel/plugin-transform-dotall-regex@7.18.6 None 0 3.13 kB nicolo-ribaudo
npm/@babel/plugin-transform-duplicate-keys@7.18.9 None 0 4.26 kB nicolo-ribaudo
npm/@babel/plugin-transform-exponentiation-operator@7.18.6 None 0 3.33 kB nicolo-ribaudo
npm/@babel/plugin-transform-for-of@7.21.0 None 0 42.6 kB nicolo-ribaudo
npm/@babel/plugin-transform-function-name@7.18.9 None 0 3.68 kB nicolo-ribaudo
npm/@babel/plugin-transform-literals@7.18.9 None 0 3.04 kB nicolo-ribaudo
npm/@babel/plugin-transform-member-expression-literals@7.18.6 None 0 3.28 kB nicolo-ribaudo
npm/@babel/plugin-transform-modules-amd@7.20.11 None 0 20 kB nicolo-ribaudo
npm/@babel/plugin-transform-modules-commonjs@7.21.2 None 0 31.3 kB nicolo-ribaudo
npm/@babel/plugin-transform-modules-systemjs@7.20.11 None 0 64.2 kB nicolo-ribaudo
npm/@babel/plugin-transform-modules-umd@7.18.6 None 0 9.49 kB nicolo-ribaudo
npm/@babel/plugin-transform-named-capturing-groups-regex@7.20.5 None 0 4.68 kB nicolo-ribaudo
npm/@babel/plugin-transform-new-target@7.18.6 None 0 4.79 kB nicolo-ribaudo
npm/@babel/plugin-transform-object-super@7.18.6 None 0 3.68 kB nicolo-ribaudo
npm/@babel/plugin-transform-parameters@7.24.1 None 0 64.9 kB nicolo-ribaudo
npm/@babel/plugin-transform-property-literals@7.18.6 None 0 3.16 kB nicolo-ribaudo
npm/@babel/plugin-transform-regenerator@7.20.5 None 0 6.04 kB nicolo-ribaudo
npm/@babel/plugin-transform-reserved-words@7.18.6 None 0 2.97 kB nicolo-ribaudo
npm/@babel/plugin-transform-shorthand-properties@7.18.6 None 0 3.96 kB nicolo-ribaudo
npm/@babel/plugin-transform-spread@7.20.7 None 0 20.8 kB nicolo-ribaudo
npm/@babel/plugin-transform-sticky-regex@7.18.6 None 0 3.1 kB nicolo-ribaudo
npm/@babel/plugin-transform-template-literals@7.18.9 None 0 6.24 kB nicolo-ribaudo
npm/@babel/plugin-transform-typeof-symbol@7.18.9 None 0 4.92 kB nicolo-ribaudo
npm/@babel/plugin-transform-typescript@7.21.0 None 0 121 kB nicolo-ribaudo
npm/@babel/plugin-transform-unicode-escapes@7.18.10 None 0 6.01 kB nicolo-ribaudo
npm/@babel/plugin-transform-unicode-regex@7.18.6 None 0 2.96 kB nicolo-ribaudo
npm/@babel/preset-env@7.20.2 environment 0 129 kB nicolo-ribaudo
npm/@babel/preset-modules@0.1.6 None 0 38.8 kB nicolo-ribaudo
npm/@babel/preset-typescript@7.21.0 None 0 14.1 kB nicolo-ribaudo
npm/@babel/regjsgen@0.8.0 None 0 15.4 kB nicolo-ribaudo
npm/@babel/runtime-corejs3@7.24.4 None +1 373 kB nicolo-ribaudo
npm/@babel/template@7.24.0 None 0 68.9 kB nicolo-ribaudo
npm/@babel/traverse@7.24.1 None 0 615 kB nicolo-ribaudo
npm/@babel/types@7.24.0 environment 0 2.41 MB nicolo-ribaudo
npm/@chevrotain/types@9.1.0 None 0 86.3 kB bd82
npm/@chevrotain/utils@9.1.0 None 0 30.5 kB bd82
npm/@cspotcode/source-map-support@0.8.1 filesystem +1 194 kB cspotcode
npm/@fastify/ajv-compiler@3.5.0 Transitive: eval +2 1.1 MB matteo.collina
npm/@fastify/deepmerge@1.3.0 None 0 14.3 kB matteo.collina
npm/@fastify/error@3.2.0 None 0 11.6 kB matteo.collina
npm/@fastify/fast-json-stringify-compiler@4.2.0 eval 0 22 kB matteo.collina
npm/@gwhitney/detect-indent@7.0.1 None 0 10.4 kB gwhitney
npm/@iarna/toml@3.0.0 eval 0 100 kB iarna
npm/@istanbuljs/load-nyc-config@1.1.0 environment, filesystem Transitive: eval, unsafe +4 436 kB coreyfarrell
npm/@jest/console@29.4.3 None +5 112 kB simenb
npm/@jest/core@29.4.3 unsafe +2 280 kB simenb
npm/@jest/environment@29.7.0 None 0 15.9 kB simenb
npm/@jest/expect-utils@29.7.0 None +1 32.1 kB simenb
npm/@jest/expect@29.7.0 None 0 5.23 kB simenb
npm/@jest/fake-timers@29.7.0 None 0 26.3 kB simenb
npm/@jest/globals@29.7.0 None 0 5.26 kB simenb
npm/@jest/reporters@29.7.0 environment, unsafe Transitive: filesystem +2 189 kB simenb
npm/@jest/source-map@29.6.3 None 0 5.07 kB simenb
npm/@jest/test-result@29.7.0 None 0 15.8 kB simenb
npm/@jest/test-sequencer@29.7.0 None 0 13.6 kB simenb
npm/@jest/transform@29.7.0 Transitive: filesystem +2 80.4 kB simenb
npm/@jest/types@29.6.3 None +2 481 kB simenb
npm/@jridgewell/gen-mapping@0.1.1 None 0 52.4 kB jridgewell
npm/@jridgewell/trace-mapping@0.3.25 None 0 169 kB jridgewell
npm/@jsdevtools/ono@7.1.3 None 0 105 kB jamesmessinger
npm/@kwsites/file-exists@1.1.1 filesystem 0 14.4 kB steveukx
npm/@kwsites/promise-deferred@1.1.1 None 0 6.2 kB steveukx
npm/@modjo/config@1.2.6 None 0 1.08 kB devthejo
npm/@modjo/core@1.2.6 Transitive: environment, filesystem, shell +1 195 kB devthejo
npm/@modjo/express@1.2.6 None 0 3.65 kB devthejo
npm/@modjo/http-logger@1.5.0 None 0 1.09 kB devthejo
npm/@modjo/http-server@1.5.0 network 0 1.54 kB devthejo
npm/@modjo/lightship@1.5.0 None 0 1.43 kB devthejo
npm/@modjo/logger@1.5.0 None 0 1.29 kB devthejo
npm/@modjo/microservice-oapi@1.2.6 None 0 1.11 kB devthejo
npm/@modjo/oa@1.5.0 filesystem, network 0 22.7 kB devthejo
npm/@modjo/sentry@1.2.6 environment 0 752 B devthejo
npm/@modjo/shutdown-handlers@1.5.0 None 0 774 B devthejo
npm/@npmcli/fs@3.1.0 filesystem 0 26.5 kB lukekarrys
npm/@npmcli/move-file@2.0.1 filesystem Transitive: environment +1 27.8 kB gar
npm/@octokit/auth-token@3.0.4 None 0 24.2 kB octokitbot
npm/@octokit/core@4.2.4 None 0 43.7 kB octokitbot
npm/@octokit/endpoint@7.0.6 None 0 87.4 kB octokitbot
npm/@octokit/graphql@5.0.6 None 0 38.7 kB octokitbot
npm/@octokit/openapi-types@18.1.1 None 0 4.23 MB octokitbot
npm/@octokit/plugin-paginate-rest@6.1.2 None +1 198 kB octokitbot
npm/@octokit/plugin-request-log@1.0.4 None 0 11.6 kB gr2m
npm/@octokit/plugin-rest-endpoint-methods@7.2.3 None +1 1.73 MB octokitbot
npm/@octokit/request-error@3.0.3 None 0 21.7 kB octokitbot
npm/@octokit/request@6.2.8 network 0 54.7 kB octokitbot
npm/@octokit/rest@19.0.13 None 0 9.82 kB octokitbot
npm/@octokit/types@9.3.2 None 0 228 kB octokitbot
npm/@one-ini/wasm@0.1.1 filesystem 0 98 kB hildjj
npm/@opentelemetry/api@1.4.1 None 0 780 kB dyladan
npm/@opentelemetry/context-async-hooks@1.14.0 unsafe 0 59.2 kB pichlermarc
npm/@opentelemetry/core@1.14.0 environment, unsafe 0 873 kB pichlermarc
npm/@opentelemetry/exporter-trace-otlp-http@0.40.0 None 0 91.1 kB pichlermarc
npm/@opentelemetry/instrumentation-bunyan@0.31.4 None 0 32.7 kB dyladan
npm/@opentelemetry/instrumentation-http@0.40.0 None 0 175 kB pichlermarc
npm/@opentelemetry/instrumentation@0.40.0 None +1 373 kB pichlermarc
npm/@opentelemetry/otlp-exporter-base@0.40.0 network 0 299 kB pichlermarc
npm/@opentelemetry/otlp-transformer@0.40.0 None +2 871 kB pichlermarc
npm/@opentelemetry/propagator-b3@1.14.0 None 0 143 kB pichlermarc
npm/@opentelemetry/propagator-jaeger@1.14.0 None 0 80.6 kB pichlermarc
npm/@opentelemetry/resources@1.14.0 environment, filesystem, shell 0 503 kB pichlermarc
npm/@opentelemetry/sdk-metrics@1.14.0 None 0 1.84 MB pichlermarc
npm/@opentelemetry/sdk-trace-base@1.14.0 None 0 759 kB pichlermarc
npm/@opentelemetry/sdk-trace-node@1.14.0 None 0 31.7 kB pichlermarc
npm/@opentelemetry/semantic-conventions@1.14.0 None 0 594 kB pichlermarc
npm/@pnpm/constants@6.1.0 None 0 3.39 kB pnpmuser
npm/@pnpm/error@4.0.0 None 0 7.21 kB pnpmuser
npm/@pnpm/graceful-fs@2.0.0 None 0 3.42 kB pnpmuser
npm/@pnpm/read-project-manifest@4.1.1 filesystem +1 24.1 kB pnpmuser
npm/@pnpm/text.comments-parser@1.0.0 None 0 15.9 kB pnpmuser
npm/@pnpm/types@8.9.0 None 0 11.1 kB pnpmuser
npm/@pnpm/util.lex-comparator@1.0.0 None 0 10.1 kB zkochan
npm/@pnpm/write-project-manifest@4.1.1 filesystem 0 6.27 kB pnpmuser
npm/@qnighy/marshal@0.1.3 None 0 39.5 kB qnighy
npm/@redis/bloom@1.2.0 None 0 61.9 kB leibale
npm/@redis/client@1.5.8 network 0 588 kB leibale
npm/@redis/graph@1.1.0 None 0 25.1 kB leibale
npm/@redis/json@1.0.4 None 0 23.1 kB leibale
npm/@redis/search@1.1.3 None 0 75.6 kB leibale
npm/@redis/time-series@1.0.4 None 0 48.7 kB leibale
npm/@renovatebot/osv-offline-db@1.4.0 None 0 10.4 kB renovate-bot
npm/@renovatebot/osv-offline@1.3.0 environment, filesystem 0 9.52 kB renovate-bot
npm/@renovatebot/pep440@2.1.18 None 0 34.9 kB renovate-bot
npm/@renovatebot/ruby-semver@3.0.3 None 0 38.2 kB renovate-bot
npm/@seald-io/binary-search-tree@1.0.3 None 0 35.3 kB seald
npm/@seald-io/nedb@4.0.4 filesystem 0 713 kB seald
npm/@sentry/hub@6.19.7 None +2 1.46 MB sentry-bot
npm/@sentry/minimal@6.19.7 None 0 56.6 kB sentry-bot
npm/@sindresorhus/is@4.6.0 None 0 57.5 kB sindresorhus
npm/@sinonjs/commons@3.0.1 None 0 38 kB mrgnrdrck
npm/@sinonjs/fake-timers@10.3.0 eval 0 80.1 kB fatso83
npm/@szmarczak/http-timer@4.0.6 None 0 10.8 kB szmarczak
npm/@thi.ng/api@7.2.0 environment 0 140 kB thi.ng
npm/@thi.ng/arrays@1.0.3 None 0 125 kB thi.ng
npm/@thi.ng/checks@2.9.11 None 0 69.8 kB thi.ng
npm/@thi.ng/compare@1.3.34 None 0 36.4 kB thi.ng
npm/@thi.ng/equiv@1.0.45 None 0 30.6 kB thi.ng
npm/@thi.ng/errors@1.3.4 None 0 29.9 kB thi.ng
npm/@thi.ng/hex@1.0.4 None 0 33.5 kB thi.ng
npm/@thi.ng/random@2.4.8 None 0 99.2 kB thi.ng
npm/@thi.ng/zipper@1.0.3 None 0 54.6 kB thi.ng
npm/@tsconfig/node10@1.0.9 None 0 2.39 kB typescript-deploys
npm/@tsconfig/node12@1.0.11 None 0 2.5 kB typescript-deploys
npm/@tsconfig/node14@1.0.3 None 0 2.39 kB typescript-deploys
npm/@tsconfig/node16@1.0.3 None 0 2.39 kB typescript-deploys
npm/@types/babel__core@7.20.5 None 0 33 kB types
npm/@types/babel__generator@7.6.8 None 0 11.4 kB types
npm/@types/babel__template@7.4.4 None 0 6.41 kB types
npm/@types/babel__traverse@7.20.5 None 0 84.1 kB types
npm/@types/body-parser@1.19.5 None 0 7.65 kB types
npm/@types/bunyan@1.8.7 None 0 11.1 kB types
npm/@types/cacheable-request@6.0.3 None 0 9.28 kB types
npm/@types/chai@4.3.4 None 0 77.9 kB types
npm/@types/connect@3.4.38 None 0 5.91 kB types
npm/@types/emscripten@1.39.10 None 0 15.1 kB types
npm/@types/express-serve-static-core@4.19.0 None 0 46 kB types
npm/@types/express@4.17.21 None 0 7.86 kB types
npm/@types/graceful-fs@4.1.9 None 0 3.9 kB types
npm/@types/http-cache-semantics@4.0.4 None 0 9.28 kB types
npm/@types/istanbul-lib-report@3.0.3 None 0 7.92 kB types
npm/@types/istanbul-reports@3.0.4 None 0 6.68 kB types
npm/@types/json5@0.0.29 None 0 3 kB types
npm/@types/keyv@3.1.4 None 0 6.12 kB types
npm/@types/lodash@4.17.0 None 0 862 kB types
npm/@types/mdast@3.0.15 None 0 11.1 kB types
npm/@types/mime@3.0.1 None 0 3.57 kB types
npm/@types/moo@0.5.5 None 0 7.24 kB types
npm/@types/ms@0.7.31 None 0 2.88 kB types
npm/@types/multer@1.4.11 None 0 16.7 kB types
npm/@types/node@20.12.7 None 0 2.03 MB types
npm/@types/qs@6.9.14 None 0 7.29 kB types
npm/@types/range-parser@1.2.7 None 0 4.62 kB types
npm/@types/responselike@1.0.3 None 0 4.6 kB types
npm/@types/serve-static@1.15.7 None 0 7.79 kB types
npm/@types/source-map-support@0.4.2 None 0 4 kB types
npm/@types/tmp@0.2.3 None 0 10.9 kB types
npm/@types/treeify@1.0.3 None 0 3.53 kB types
npm/@types/unist@2.0.10 None 0 8.56 kB types
npm/@types/yargs@17.0.32 None 0 60.2 kB types
npm/@types/yauzl@2.10.3 None 0 6.11 kB types
npm/@vercel/ncc@0.36.1 filesystem, unsafe 0 15.9 MB vercel-release-bot
npm/@yarnpkg/core@3.5.2 environment, eval, filesystem, network, unsafe +2 797 kB yarnbot
npm/@yarnpkg/fslib@2.10.4 filesystem 0 276 kB yarnbot
npm/@yarnpkg/json-proxy@2.1.1 None 0 11.9 kB arcanis
npm/@yarnpkg/libzip@2.3.0 filesystem 0 769 kB arcanis
npm/@yarnpkg/parsers@2.5.1 None 0 195 kB arcanis
npm/@yarnpkg/pnp@3.3.7 environment, filesystem, unsafe +1 2.61 MB yarnbot
npm/@yarnpkg/shell@3.3.0 environment, filesystem +1 256 kB yarnbot
npm/abort-controller@3.0.0 None 0 76.3 kB mysticatea
npm/abstract-logging@2.0.1 None 0 2.3 kB jsumners
npm/accepts@1.3.8 None 0 16.8 kB dougwilson
npm/acorn-walk@8.2.0 None 0 42.8 kB marijn
npm/adm-zip@0.5.12 filesystem 0 104 kB cthackers
npm/agentkeepalive@4.3.0 network 0 42.8 kB fengmk2
npm/aggregate-error@3.1.0 None 0 6.69 kB sindresorhus
npm/ajv-formats@2.1.1 None 0 52.2 kB esp
npm/ansi-align@3.0.1 None 0 7.68 kB nexdrew
npm/any-promise@1.3.0 None 0 22.2 kB kevinbeaty
npm/append-field@1.0.0 None 0 6.04 kB linusu
npm/are-we-there-yet@3.0.1 None 0 14.3 kB lukekarrys
npm/arg@4.1.3 None 0 12.9 kB qix
npm/args@5.0.3 environment, filesystem, shell +3 50.5 kB leo
npm/array-flatten@3.0.0 None 0 20.1 kB blakeembrey
npm/asap@2.0.6 None 0 33.9 kB kriskowal
npm/asn1.js@5.4.1 None 0 49.8 kB indutny
npm/assertion-error@1.1.0 None 0 5.64 kB chaijs
npm/astral-regex@2.0.0 None 0 3.4 kB kevva
npm/auth-header@1.0.0 None 0 21.6 kB izaakschroeder
npm/avvio@8.3.0 None +1 198 kB matteo.collina
npm/aws4@1.12.0 environment 0 23.5 kB hichaelmart
npm/azure-devops-node-api@12.1.0 environment, filesystem 0 4.35 MB tkasparek_ms
npm/babel-jest@29.7.0 environment 0 13.5 kB simenb
npm/babel-plugin-istanbul@6.1.1 environment, filesystem, shell +1 95.9 kB oss-bot
npm/babel-plugin-jest-hoist@29.6.3 None 0 14.3 kB simenb
npm/babel-plugin-polyfill-corejs2@0.3.3 None 0 80.5 kB nicolo-ribaudo
npm/babel-plugin-polyfill-corejs3@0.6.0 None 0 170 kB nicolo-ribaudo
npm/babel-plugin-polyfill-regenerator@0.4.1 None 0 8.65 kB nicolo-ribaudo
npm/babel-preset-current-node-syntax@1.0.1 eval 0 5.46 kB nicolo-ribaudo
npm/babel-preset-jest@29.6.3 None 0 2.69 kB simenb
npm/backslash@0.2.0 None 0 8.74 kB qix
npm/bail@1.0.5 None 0 4.3 kB wooorm
npm/before-after-hook@2.2.3 None 0 37 kB gr2m
npm/bn.js@4.12.0 None 0 95.7 kB fanatid
npm/body-parser@2.0.0-beta.2 network Transitive: environment, unsafe +5 711 kB dougwilson
npm/boolbase@1.0.0 None 0 1.33 kB feedic
npm/boolean@3.2.0 None 0 12.5 kB thenativeweb-admin
npm/bowser@2.11.0 None 0 217 kB lancedikson
npm/boxen@4.2.0 None +1 70.6 kB sindresorhus
npm/browserslist@4.23.0 environment, filesystem 0 62.8 kB ai
npm/bser@2.1.1 None 0 18 kB wez
npm/buffer@5.7.1 None +1 92.2 kB feross
npm/builtins@5.1.0 None 0 3.7 kB juliangruber
npm/bunyan@1.8.15 environment, filesystem 0 201 kB trentm
npm/busboy@1.6.0 None 0 124 kB mscdex
npm/bytes@3.1.2 None 0 12.3 kB dougwilson
npm/cacache@17.1.3 filesystem +1 198 kB npm-cli-ops
npm/cacheable-lookup@5.0.4 network 0 23.9 kB szmarczak
npm/cacheable-request@7.0.4 network +1 29.1 kB jaredwray
npm/call-me-maybe@1.0.2 None 0 3.79 kB limulus
npm/chai@4.3.7 None 0 752 kB chai
npm/changelog-filename-regex@2.0.1 None 0 4.16 kB shinnn
npm/character-entities-legacy@1.1.4 None 0 6.71 kB wooorm
npm/character-entities@1.2.4 None 0 47.7 kB wooorm
npm/character-reference-invalid@1.1.4 None 0 5.54 kB wooorm
npm/check-error@1.0.3 None 0 14.4 kB keithamus
npm/chevrotain@9.1.0 None 0 2.35 MB bd82
npm/clean-git-ref@2.0.1 None 0 2.33 kB eliwhite
npm/cli-boxes@2.2.1 None 0 6.14 kB sindresorhus
npm/cli-color@2.0.3 None 0 39.6 kB medikoo
npm/cli-highlight@2.1.11 Transitive: environment, filesystem +5 518 kB felixfbecker
npm/clipanion@3.2.0-rc.4 environment 0 207 kB arcanis
npm/clone-response@1.0.3 None 0 4.53 kB sindresorhus
npm/cluster-key-slot@1.1.2 None 0 12.2 kB salakar
npm/component-emitter@1.3.0 None 0 8 kB nami-doc
npm/configstore@5.0.1 Transitive: filesystem +2 30.4 kB sindresorhus
npm/content-disposition@0.5.4 None 0 19.1 kB dougwilson
npm/content-type@1.0.5 None 0 10.5 kB dougwilson
npm/conventional-commits-detector@1.0.3 Transitive: filesystem +8 282 kB hutson
npm/convert-source-map@1.9.0 filesystem 0 11.4 kB thlorenz
npm/cookie-parser@1.4.6 None +1 30.2 kB dougwilson
npm/cookie-signature@1.0.6 None 0 3.94 kB natevw
npm/cookiejar@2.1.4 None 0 14.5 kB andyburke
npm/core-js-compat@3.36.1 None 0 717 kB zloirock
npm/core-js-pure@3.36.1 environment, eval, filesystem 0 1.07 MB zloirock
npm/cors@2.8.5 None 0 20 kB dougwilson
npm/create-require@1.1.1 filesystem, unsafe 0 6.25 kB pi0
npm/crypto-random-string@2.0.0 None 0 3.93 kB sindresorhus
npm/css-select@5.1.0 None 0 224 kB feedic
npm/css-what@6.1.0 None 0 66 kB feedic
npm/d@1.0.2 None 0 14.2 kB medikoo
npm/decompress-response@6.0.0 None +1 11.5 kB sindresorhus
npm/deep-eql@4.1.3 None 0 24.2 kB chai
npm/deep-extend@0.6.0 None 0 9.19 kB unclechu
npm/defer-to-connect@2.0.1 None 0 5.44 kB szmarczak
npm/delay@5.0.0 None 0 11.2 kB sindresorhus
npm/depd@2.0.0 environment, eval 0 27.1 kB dougwilson
npm/deprecation@2.3.1 None 0 4.01 kB gr2m
npm/dequal@2.0.3 None 0 14.2 kB lukeed
npm/destroy@1.2.0 filesystem 0 9.02 kB dougwilson
npm/detect-node@2.1.0 None 0 2.76 kB iliakan
npm/dezalgo@1.0.4 None 0 2.96 kB gar
npm/diff@5.2.0 None 0 429 kB explodingcabbage
npm/dom-serializer@2.0.0 None +1 442 kB feedic
npm/domelementtype@2.3.0 None 0 11.4 kB feedic
npm/domhandler@5.0.3 None 0 75.3 kB feedic
npm/domutils@3.1.0 network 0 162 kB feedic
npm/dree@4.4.3 filesystem Transitive: environment +2 260 kB euberdeveloper
npm/dtrace-provider@0.8.8 environment 0 88.3 kB melloc
npm/duplexify@4.1.3 None 0 18.3 kB mafintosh
npm/editorconfig@1.0.3 filesystem Transitive: environment +1 463 kB hildjj
npm/email-addresses@5.0.0 None 0 130 kB jackbowman
npm/emojibase-regex@6.0.1 None 0 137 kB milesj
npm/emojibase@6.1.0 network 0 103 kB milesj
npm/encoding@0.1.13 None 0 7.12 kB andris
npm/end-of-stream@1.4.4 None 0 6.23 kB mafintosh

🚮 Removed packages: npm/commander@10.0.1, npm/enquirer@2.4.1, npm/env-paths@2.2.1, npm/err-code@2.0.3, npm/error-ex@1.3.2, npm/es-abstract@1.23.3, npm/es-set-tostringtag@2.0.3, npm/es-shim-unscopables@1.0.2, npm/es-to-primitive@1.2.1, npm/es6-error@4.1.1, npm/escalade@3.1.2, npm/escape-html@1.0.3, npm/escape-string-regexp@1.0.5, npm/eslint-config-airbnb-base@15.0.0, npm/eslint-config-prettier@8.10.0, npm/eslint-import-resolver-alias@1.1.2, npm/eslint-import-resolver-node@0.3.9, npm/eslint-module-utils@2.8.1, npm/eslint-plugin-es@3.0.1, npm/eslint-plugin-import@2.29.1, npm/eslint-plugin-jest@27.9.0, npm/eslint-plugin-node@11.1.0, npm/eslint-plugin-prettier@4.2.1, npm/eslint-scope@7.2.2, npm/eslint-utils@2.1.0, npm/eslint-visitor-keys@3.4.3, npm/eslint@8.57.0, npm/espree@9.6.1, npm/esprima@4.0.1, npm/esquery@1.5.0, npm/esrecurse@4.3.0, npm/estraverse@4.3.0, npm/esutils@2.0.3, npm/eventemitter3@5.0.1, npm/execa@7.2.0, npm/exit@0.1.2, npm/fast-deep-equal@3.1.3, npm/fast-diff@1.3.0, npm/fast-glob@3.3.2, npm/fast-json-stable-stringify@2.1.0, npm/fast-levenshtein@2.0.6, npm/fastq@1.17.1, npm/figures@3.2.0, npm/file-entry-cache@6.0.1, npm/fill-range@7.0.1, npm/finalhandler@1.1.2, npm/find-up@5.0.0, npm/flat-cache@3.2.0, npm/flatted@3.3.1, npm/form-data@4.0.0, npm/fs-extra@11.2.0, npm/fs.realpath@1.0.0, npm/fsevents@2.3.3, npm/function-bind@1.1.2, npm/function.prototype.name@1.1.6, npm/functions-have-names@1.2.3, npm/gensync@1.0.0-beta.2, npm/get-caller-file@2.0.5, npm/get-intrinsic@1.2.4, npm/get-package-type@0.1.0, npm/get-pkg-repo@4.2.1, npm/get-port@5.1.1, npm/get-stream@2.3.1, npm/get-symbol-description@1.0.2, npm/git-raw-commits@2.0.11, npm/git-remote-origin-url@2.0.0, npm/git-semver-tags@5.0.1, npm/gitconfiglocal@1.0.0, npm/glob-parent@6.0.2, npm/globals@13.24.0, npm/globalthis@1.0.3, npm/globby@11.1.0, npm/gopd@1.0.1, npm/graceful-fs@4.2.10, npm/handlebars@4.7.8, npm/hard-rejection@2.1.0, npm/has-flag@4.0.0, npm/has-property-descriptors@1.0.2, npm/has-proto@1.0.3, npm/has-symbols@1.0.3, npm/has-tostringtag@1.0.2, npm/has-unicode@2.0.1, npm/hosted-git-info@4.1.0, npm/html-escaper@2.0.2, npm/http-cache-semantics@4.1.1, npm/human-signals@4.3.1, npm/husky@8.0.3, npm/ignore@5.3.1, npm/import-fresh@3.3.0, npm/imurmurhash@0.1.4, npm/indent-string@4.0.0, npm/infer-owner@1.0.4, npm/inherits@2.0.4, npm/ini@1.3.8, npm/internal-slot@1.0.7, npm/ip@2.0.0, npm/is-array-buffer@3.0.4, npm/is-arrayish@0.2.1, npm/is-binary-path@2.1.0, npm/is-callable@1.2.7, npm/is-core-module@2.13.1, npm/is-date-object@1.0.5, npm/is-extglob@2.1.1, npm/is-generator-fn@2.1.0, npm/is-glob@4.0.3, npm/is-lambda@1.0.1, npm/is-negative-zero@2.0.3, npm/is-number@7.0.0, npm/is-obj@2.0.0, npm/is-path-inside@3.0.3, npm/is-plain-obj@1.1.0, npm/is-regex@1.1.4, npm/is-shared-array-buffer@1.0.3, npm/is-stream@1.1.0, npm/is-string@1.0.7, npm/is-symbol@1.0.4, npm/is-text-path@1.0.1, npm/is-typed-array@1.1.13, npm/is-weakref@1.0.2, npm/is-wsl@1.1.0, npm/istanbul-lib-coverage@3.2.2, npm/jest-diff@29.4.3, npm/jest-regex-util@29.6.3, npm/js-tokens@4.0.0, npm/js-yaml@4.1.0, npm/jsesc@2.5.2, npm/json-buffer@3.0.1, npm/json-parse-better-errors@1.0.2, npm/json-parse-even-better-errors@2.3.1, npm/json-schema-traverse@0.4.1, npm/json-stable-stringify-without-jsonify@1.0.1, npm/json-stringify-safe@5.0.1, npm/json5@2.2.3, npm/jsonfile@6.1.0, npm/jsonparse@1.3.1, npm/keyv@4.5.4, npm/kind-of@6.0.3, npm/kleur@3.0.3, npm/leven@3.1.0, npm/levn@0.4.1, npm/lilconfig@2.1.0, npm/lines-and-columns@1.2.4, npm/lint-staged@13.3.0, npm/listr2@6.6.1, npm/livereload-js@3.4.1, npm/livereload@0.9.3, npm/load-json-file@4.0.0, npm/locate-path@5.0.0, npm/lodash.camelcase@4.3.0, npm/lodash.clonedeep@4.5.0, npm/lodash.defaults@4.2.0, npm/lodash.get@4.4.2, npm/lodash.ismatch@4.4.0, npm/lodash.kebabcase@4.1.1, npm/lodash.merge@4.6.2, npm/lodash.omit@4.5.0, npm/lodash.pick@4.4.0, npm/lodash.set@4.3.2, npm/lodash@4.17.21, npm/log-update@5.0.1, npm/lru-cache@5.1.1, npm/make-dir@1.3.0, npm/map-obj@4.3.0, npm/marked@1.2.9, npm/medium-zoom@1.1.0, npm/meow@8.1.2, npm/merge-stream@2.0.0, npm/micromatch@4.0.5, npm/mime-types@2.1.35, npm/mimic-fn@4.0.0, npm/minimatch@3.1.2, npm/minimist-options@4.1.0, npm/minimist@1.2.8, npm/minipass@5.0.0, npm/modify-values@1.0.1, npm/natural-compare@1.4.0, npm/nctx@2.2.0, npm/negotiator@0.6.3, npm/neo-async@2.6.2, npm/nested-error-stacks@2.1.1, npm/node-fetch@2.7.0, npm/node-int64@0.4.0, npm/node-releases@2.0.14, npm/normalize-package-data@3.0.3, npm/normalize-path@3.0.0, npm/npm-run-path@5.3.0, npm/object-assign@4.1.1, npm/object-inspect@1.13.1, npm/object-keys@1.1.1, npm/object.assign@4.1.5, npm/object.entries@1.1.8, npm/object.values@1.2.0, npm/on-finished@2.3.0, npm/onetime@6.0.0, npm/open@6.4.0, npm/opencollective-postinstall@2.0.3, npm/optionator@0.9.3, npm/opts@2.0.2, npm/p-event@4.2.0, npm/p-finally@1.0.0, npm/p-limit@3.1.0, npm/p-locate@3.0.0, npm/p-timeout@3.2.0, npm/p-try@2.2.0, npm/parent-module@1.0.1, npm/parse-json@5.2.0, npm/parse-url@8.1.0, npm/parseurl@1.3.3, npm/path-exists@4.0.0, npm/path-is-absolute@1.0.1, npm/path-key@3.1.1, npm/path-parse@1.0.7, npm/path-type@4.0.0, npm/picocolors@1.0.0, npm/picomatch@2.3.1, npm/pidtree@0.6.0, npm/pirates@4.0.6, npm/prelude-ls@1.2.1, npm/prettier-linter-helpers@1.0.0, npm/prettier@2.8.8, npm/prismjs@1.29.0, npm/promise-inflight@1.0.1, npm/protocols@2.0.1, npm/punycode@2.3.1, npm/q@1.5.1, npm/quick-lru@4.0.1, npm/read-pkg-up@3.0.0, npm/read-pkg@3.0.0, npm/readable-stream@3.6.2, npm/readdirp@3.6.0, npm/redent@3.0.0, npm/regexp.prototype.flags@1.5.2, npm/regexpp@3.2.0, npm/renovate@35.159.7, npm/replace@1.2.2, npm/resolve-from@4.0.0, npm/resolve-pathname@3.0.0, npm/resolve.exports@2.0.2, npm/resolve@1.22.8, npm/restore-cursor@4.0.0, npm/retry@0.13.1, npm/reusify@1.0.4, npm/rfdc@1.3.1, npm/rimraf@3.0.2, npm/run-parallel@1.2.0, npm/safe-regex-test@1.0.3, npm/safer-buffer@2.1.2, npm/semver@7.6.0, npm/serve-static@1.15.0, npm/shebang-command@2.0.0, npm/shebang-regex@3.0.0, npm/side-channel@1.0.6, npm/signal-exit@3.0.7, npm/sisteransi@1.0.5, npm/slash@3.0.0, npm/slice-ansi@5.0.0, npm/slugify@1.6.5, npm/smart-buffer@4.2.0, npm/sonic-boom@3.2.1, npm/source-map@0.6.1, npm/split2@3.2.2, npm/split@1.0.1, npm/sprintf-js@1.0.3, npm/statuses@1.5.0, npm/string-argv@0.3.2, npm/string-width@4.2.3, npm/string.prototype.trimend@1.0.8, npm/string.prototype.trimstart@1.0.8, npm/string_decoder@1.1.1, npm/strip-ansi@6.0.1, npm/strip-bom@3.0.0, npm/strip-final-newline@3.0.0, npm/strip-indent@3.0.0, npm/strip-json-comments@3.1.1, npm/supports-color@5.5.0, npm/supports-preserve-symlinks-flag@1.0.0, npm/text-extensions@1.9.0, npm/text-table@0.2.0, npm/through2@4.0.2, npm/through@2.3.8, npm/tiged@2.12.4, npm/tinydate@1.3.0, npm/tmpl@1.0.5, npm/to-fast-properties@2.0.0, npm/to-regex-range@5.0.1, npm/trim-newlines@3.0.1, npm/tsconfig-paths@3.15.0, npm/tslib@1.14.1, npm/tsutils@3.21.0, npm/tweezer.js@1.5.0, npm/type-check@0.4.0, npm/type-detect@4.0.8, npm/type-fest@0.20.2, npm/typed-array-length@1.0.6, npm/typedarray@0.0.6, npm/typescript@4.9.5, npm/uglify-js@3.17.4, npm/unbox-primitive@1.0.2, npm/universalify@2.0.0, npm/unpipe@1.0.0, npm/update-notifier@4.1.3, npm/uri-js@4.4.1, npm/util-deprecate@1.0.2, npm/utils-merge@1.0.1, npm/validate-npm-package-license@3.0.4, npm/whatwg-url@5.0.0, npm/which-typed-array@1.1.15, npm/which@3.0.0, npm/wordwrap@1.0.0, npm/wrap-ansi@6.2.0, npm/wrappy@1.0.2, npm/ws@7.5.9, npm/xtend@4.0.2, npm/y18n@4.0.3, npm/yallist@4.0.0, npm/yaml@2.3.1, npm/yargonaut@1.1.4, npm/yargs-parser@18.1.3, npm/yargs@17.7.2, npm/yauzl@2.10.0, npm/yocto-queue@0.1.0, npm/zx@7.2.0

View full report↗︎

socket-security[bot] commented 6 months ago

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSource
Install scripts npm/@modjo/core@1.2.6
  • Install script: postinstall
  • Source: link-module-alias
Install scripts npm/core-js-pure@3.36.1
  • Install script: postinstall
  • Source: node -e "try{require('./postinstall')}catch(e){}"

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/@modjo/core@1.2.6
  • @SocketSecurity ignore npm/core-js-pure@3.36.1