anza-xyz / octane

Octane is a gasless transaction relayer for Solana.
Apache License 2.0
218 stars 128 forks source link

Move main logic to testable library functions; Use Next.js instead of Vercel functions #12

Closed sevazhidkov closed 2 years ago

sevazhidkov commented 2 years ago

Hey!

In this PR:

Tests and library setup were commited separately, if you would like to review it subsequently.

socket-security[bot] commented 2 years ago

Socket Security Report

šŸ“œ New install scripts detected

A dependency change in this PR is introducing new install scripts to your install step.

Package Script field Location
bufferutil@4.0.6 (upgraded) binding.gyp packages/core/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0,packages/server/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0
fibers@5.0.1 (added) binding.gyp packages/server/package.json via next@12.2.2
node-sass@7.0.1 (added) binding.gyp packages/server/package.json via next@12.2.2
secp256k1@4.0.3 (upgraded) binding.gyp packages/core/package.json via @solana/web3.js@1.48.0,packages/server/package.json via @solana/web3.js@1.48.0
utf-8-validate@5.0.9 (upgraded) binding.gyp packages/core/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0,packages/server/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0
node-sass@7.0.1 (added) install packages/server/package.json via next@12.2.2
node-sass@7.0.1 (added) postinstall packages/server/package.json via next@12.2.2
secp256k1@4.0.3 (upgraded) install packages/core/package.json via @solana/web3.js@1.48.0,packages/server/package.json via @solana/web3.js@1.48.0
bufferutil@4.0.6 (upgraded) install packages/core/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0,packages/server/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0
utf-8-validate@5.0.9 (upgraded) install packages/core/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0,packages/server/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0
fibers@5.0.1 (added) install packages/server/package.json via next@12.2.2
šŸ“ž Package telemetry added

A dependency change in this PR includes telemetry.

Package Note Location
next@12.2.2 (added) Can be disabled by setting the environment variable NEXT_TELEMETRY_DISABLED=1 packages/server/package.json
šŸ«£ Native code

Contains native code which could be a vector to obscure malicious code, and generally decrease the likelihood of reproducible or reliable installs.

Package Location
bufferutil@4.0.6 (upgraded) packages/core/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0,packages/server/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0
fibers@5.0.1 (added) packages/server/package.json via next@12.2.2
node-sass@7.0.1 (added) packages/server/package.json via next@12.2.2
secp256k1@4.0.3 (upgraded) packages/core/package.json via @solana/web3.js@1.48.0,packages/server/package.json via @solana/web3.js@1.48.0
utf-8-validate@5.0.9 (upgraded) packages/core/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0,packages/server/package.json via @solana/web3.js@1.48.0, rpc-websockets@7.5.0
Socket.dev scan summary
Issue Status
Did you mean? āœ… no new possible package typos
Install scripts āš ļø 11 new install scripts detected
Telemetry āš ļø 1 new telemetry script detected
Troll package āœ… no new troll packages
Malware āœ… no new malware
Native code āš ļø 5 new native modules detected

Powered by socket.dev