blocknative / web3-onboard

Client library to onboard users to web3 apps
https://onboard.blocknative.com/
MIT License
831 stars 491 forks source link

FEAT - Add 6963 support to injected wallets module #2076

Closed Adamj1232 closed 6 months ago

Adamj1232 commented 6 months ago

Description

This PR adds 6963 support to injected wallets module

PLEASE NOTE- Checklist must be complete prior to review.

Checklist

Docs Checklist

socket-security[bot] commented 6 months ago

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@algolia/client-search@4.17.0 None +5 258 kB shortcuts
npm/@babel/code-frame@7.23.5 Transitive: environment +5 135 kB nicolo-ribaudo
npm/@babel/compat-data@7.23.5 None 0 64.6 kB nicolo-ribaudo
npm/@babel/helper-compilation-targets@7.23.6 Transitive: environment, filesystem +7 324 kB nicolo-ribaudo
npm/@babel/helper-string-parser@7.23.4 None 0 31.6 kB nicolo-ribaudo
npm/@babel/helper-validator-option@7.23.5 None 0 11.7 kB nicolo-ribaudo
npm/@babel/highlight@7.23.4 Transitive: environment +4 112 kB nicolo-ribaudo
npm/@babel/parser@7.23.6 None 0 1.89 MB nicolo-ribaudo
npm/@babel/runtime@7.23.2 None +1 275 kB nicolo-ribaudo
npm/@babel/types@7.23.6 environment +3 2.5 MB nicolo-ribaudo
npm/@docsearch/css@3.3.4 None 0 27.9 kB shortcuts
npm/@docsearch/js@3.3.4 Transitive: environment +19 10.2 MB shortcuts
npm/@emotion/react@11.11.1 environment +5 1.2 MB emotion-release-bot
npm/@iconify-json/ri@1.1.8 None +1 884 kB cyberalien
npm/@iconify/types@2.0.0 None 0 25.7 kB cyberalien
npm/@jridgewell/trace-mapping@0.3.18 None +2 259 kB jridgewell
npm/@safe-global/safe-apps-provider@0.18.0 Transitive: environment, network +18 51.4 MB dasanra
npm/@safe-global/safe-apps-sdk@8.1.0 Transitive: environment, network +16 51.3 MB dasanra
npm/@solana/web3.js@1.87.1 environment, eval, network Transitive: filesystem, shell +29 24.6 MB buffalojoec
npm/@sveltejs/adapter-static@2.0.2 environment Transitive: eval, filesystem, network, shell, unsafe +28 20.9 MB svelte-admin
npm/@sveltejs/kit@1.27.2 environment, eval Transitive: filesystem, network, shell, unsafe +27 20.9 MB svelte-admin
npm/@svelteness/kit-docs@1.1.5 Transitive: filesystem, network +12 28.7 MB mihar-22
npm/@tailwindcss/typography@0.5.9 Transitive: environment, filesystem +10 5.84 MB bradlc
npm/@types/animejs@3.1.7 None 0 8.88 kB types
npm/@types/bn.js@5.1.1 None +1 3.67 MB types
npm/@types/lodash@4.14.202 None 0 862 kB types
npm/@types/react@18.2.6 None +3 1.59 MB types
npm/@vitejs/plugin-react@4.2.1 Transitive: environment, eval, filesystem, network, shell, unsafe +54 15.7 MB vitebot
npm/@wagmi/connectors@3.1.5 Transitive: environment, network +20 51.6 MB awkweb
npm/@web3-onboard/arcana-auth@2.0.0 Transitive: network +8 11.5 MB cmeisl
npm/@web3-onboard/bitget@2.0.1 Transitive: environment, eval, filesystem, network, shell +36 36.3 MB cmeisl
npm/@web3-onboard/blocto@2.0.0 Transitive: environment, eval, filesystem, network, shell +36 36.8 MB cmeisl
npm/@web3-onboard/capsule@2.0.1 Transitive: environment, eval, network +183 139 MB cmeisl
npm/@web3-onboard/cede-store@2.2.0 None +3 11.1 MB cmeisl
npm/@web3-onboard/coinbase@2.2.5 None +3 11.1 MB cmeisl
npm/@web3-onboard/dcent@2.2.7 network +3 11.1 MB cmeisl
npm/@web3-onboard/enkrypt@2.0.4 None +3 11.1 MB cmeisl
npm/@web3-onboard/fortmatic@2.0.19 None +4 11.2 MB cmeisl
npm/@web3-onboard/frame@2.0.2 None +3 11.1 MB cmeisl
npm/@web3-onboard/frontier@2.0.4 None +3 11.1 MB cmeisl
npm/@web3-onboard/gas@2.1.8 None +4 15.6 MB cmeisl
npm/@web3-onboard/gnosis@2.1.10 None +3 11.1 MB cmeisl
npm/@web3-onboard/infinity-wallet@2.0.4 None 0 16.5 kB cmeisl
npm/@web3-onboard/keepkey@2.3.7 None +14 16.2 MB cmeisl
npm/@web3-onboard/keystone@2.3.7 None +3 11.1 MB cmeisl
npm/@web3-onboard/ledger@2.5.1 None +3 11.1 MB cmeisl
npm/@web3-onboard/magic@2.1.7 None +3 11.1 MB cmeisl
npm/@web3-onboard/metamask@2.0.2 None +3 11.1 MB cmeisl
npm/@web3-onboard/mew-wallet@2.0.4 None +4 11.1 MB cmeisl
npm/@web3-onboard/phantom@2.0.3 None +3 11.1 MB cmeisl
npm/@web3-onboard/portis@2.1.7 None +3 11.1 MB cmeisl
npm/@web3-onboard/sequence@2.0.8 None +3 11.1 MB cmeisl
npm/@web3-onboard/taho@2.0.5 None +4 11.1 MB cmeisl
npm/@web3-onboard/torus@2.2.6 None +3 11.1 MB cmeisl
npm/@web3-onboard/transaction-preview@2.0.8 None +8 22.9 MB cmeisl
npm/@web3-onboard/trezor@2.4.3 None +17 16.3 MB cmeisl
npm/@web3-onboard/trust@2.0.4 None +3 11.1 MB cmeisl
npm/@web3-onboard/uauth@2.1.1 None +3 11.1 MB cmeisl
npm/@web3-onboard/venly@2.0.0 None +3 11.1 MB cmeisl
npm/@web3-onboard/web3auth@2.2.3 Transitive: environment, eval, filesystem, network, shell +35 40.5 MB cmeisl
npm/@web3-onboard/xdefi@2.0.4 None +3 11.1 MB cmeisl
npm/@web3-onboard/zeal@2.0.4 None +3 11.1 MB cmeisl
npm/agentkeepalive@4.5.0 network 0 43.7 kB fengmk2
npm/animejs@3.2.1 None 0 109 kB juliangarnier
npm/assert-plus@1.0.0 environment 0 11.4 kB pfmooney
npm/assert@2.0.0 Transitive: environment +5 162 kB lukechilds
npm/autoprefixer@10.4.14 environment Transitive: filesystem +4 328 kB ai
npm/base64-js@1.5.1 None 0 9.62 kB feross
npm/base64url@3.0.1 None 0 7.55 kB brianloveswords
npm/bech32@1.1.4 None 0 9.98 kB junderw
npm/big-integer@1.6.51 None 0 164 kB peterolson
npm/bitcoin-ops@1.4.1 None 0 4.38 kB dcousens
npm/bn.js@5.2.1 None 0 99 kB fanatid
npm/bnc-sdk@4.6.7 None +2 881 kB cmeisl
npm/bowser@2.11.0 None 0 217 kB lancedikson
npm/brorand@1.1.0 None 0 3.52 kB indutny
npm/browserify-zlib@0.2.0 None +1 980 kB dignifiedquire
npm/browserslist@4.22.2 environment, filesystem +1 96.5 kB ai
npm/bs58@4.0.1 None +1 14 kB dcousens
npm/buffer@6.0.3 None +2 108 kB feross
npm/call-bind@1.0.2 None 0 14.7 kB ljharb
npm/camelcase@5.3.1 None 0 7.45 kB sindresorhus
npm/clone@2.1.2 None 0 15.9 kB pvorb
npm/clsx@1.2.1 None 0 5.67 kB lukeed
npm/cosmjs-types@0.8.0 None +1 23 MB webmaster128
npm/create-hash@1.2.0 None +1 9.17 kB cwmma
npm/cross-fetch@3.1.5 network +1 236 kB lquixada
npm/crypto-browserify@3.12.0 None +2 62.7 kB cwmma
npm/crypto-js@4.1.1 None 0 444 kB evanvosberg
npm/csstype@3.1.2 None 0 1.22 MB faddee
npm/debug@4.3.4 environment +1 49.2 kB qix
npm/decode-uri-component@0.2.2 None 0 6.09 kB samverschueren
npm/deepmerge@4.3.1 None 0 31.2 kB tehshrike
npm/depd@2.0.0 environment, eval 0 27.1 kB dougwilson
npm/detect-browser@5.3.0 None 0 27 kB damonoehlman
npm/elliptic@6.5.4 None +4 132 kB indutny
npm/engine.io-parser@5.2.1 None 0 46.3 kB darrachequesne
npm/es6-promise@4.2.8 None 0 315 kB stefanpenner
npm/estree-walker@2.0.2 None 0 50.2 kB rich_harris
npm/eth-rpc-errors@4.0.3 None +1 91.9 kB rekmarks
npm/ethereumjs-common@1.5.2 None 0 795 kB evertonfraga
npm/ethers@5.7.2 None 0 10.7 MB ricmoo
npm/ethjs-util@0.1.6 None +1 234 kB silentcicero
npm/eventemitter3@5.0.1 None 0 73.4 kB lpinca
npm/events@3.3.0 None 0 82.8 kB goto-bus-stop
npm/extsprintf@1.3.0 None 0 22.8 kB dap
npm/fast-safe-stringify@2.1.1 None 0 39.7 kB matteo.collina
npm/get-caller-file@2.0.5 None 0 4.72 kB stefanpenner
npm/google-protobuf@3.21.2 None 0 820 kB dibenede
npm/ieee754@1.2.1 None 0 6.8 kB feross
npm/inherits@2.0.4 None 0 3.96 kB isaacs
npm/is-docker@2.2.1 filesystem 0 3.01 kB sindresorhus
npm/is-nan@1.3.2 None +1 25.5 kB ljharb
npm/is-typedarray@1.0.0 None 0 4.41 kB hughsk
npm/jayson@4.1.0 network Transitive: filesystem, shell +9 4.19 MB tedeh
npm/js-sha3@0.8.0 None 0 52.9 kB emn178
npm/js-tokens@4.0.0 None 0 15.1 kB lydell
npm/json-rpc-random-id@1.0.1 None 0 2.12 kB kumavis
npm/json-stringify-safe@5.0.1 None 0 12.7 kB isaacs
npm/lodash.isequal@4.5.0 None 0 52.7 kB jdalton
npm/lodash@4.17.21 None 0 1.41 MB bnjmnt4n
npm/minimalistic-assert@1.0.1 None 0 1.55 kB cwmma
npm/minimist@1.2.8 None 0 54.5 kB ljharb
npm/mri@1.2.0 None 0 13.3 kB lukeed
npm/mrmime@1.0.1 None 0 31 kB lukeed
npm/ms@2.1.2 None 0 6.84 kB styfle
npm/next-tick@1.1.0 None 0 7.65 kB medikoo
npm/node-fetch@2.7.0 network 0 162 kB node-fetch-bot
npm/node-forge@1.3.1 None 0 1.66 MB davidlehn
npm/node-releases@2.0.14 None 0 34 kB chicoxyzzy
npm/normalize-path@3.0.0 None 0 9.22 kB jonschlinkert
npm/object-assign@4.1.1 None 0 5.49 kB sindresorhus
npm/object-is@1.1.5 None +1 38.1 kB ljharb
npm/picomatch@2.3.1 None 0 90 kB mrmlnc
npm/postcss-value-parser@4.2.0 None 0 27.2 kB evilebottnawi
npm/preact@10.13.2 None 0 1.21 MB jdecroock
npm/prettier-plugin-svelte@2.10.0 environment Transitive: filesystem, unsafe +2 22.1 MB dummdidumm
npm/qrcode-generator@1.4.4 None 0 117 kB kazuhikoarase
npm/react-dom@18.2.0 environment +1 4.82 MB gnoff
npm/react-is@16.13.1 environment 0 24 kB acdlite
npm/react@18.2.0 environment 0 316 kB gnoff
npm/redis-errors@1.2.0 None 0 8.85 kB bridgear
npm/rlp@2.2.7 None +1 162 kB ralxz
npm/rollup-plugin-polyfill-node@0.12.0 None 0 1.06 MB fredkschott
npm/sade@1.8.1 None +1 44.8 kB lukeed
npm/safe-buffer@5.2.1 None 0 32.1 kB feross
npm/safe-stable-stringify@2.4.3 None 0 30.1 kB bridgear
npm/safer-buffer@2.1.2 None 0 42.3 kB chalker
npm/scrypt-js@3.0.1 None 0 226 kB ricmoo
npm/sdp@2.12.0 None 0 98.8 kB fippo
npm/semaphore@1.1.0 None 0 8.13 kB addaleax
npm/shiki@0.12.1 filesystem, network +3 9.65 MB orta
npm/stream-browserify@3.0.0 None +1 15.5 kB goto-bus-stop
npm/stream-http@3.2.0 Transitive: network +3 41.7 kB jhiesey
npm/svelte-check@3.3.2 Transitive: environment, filesystem, unsafe +51 63.2 MB svelte-language-tools-deploy
npm/svelte-preprocess@5.0.3 environment, filesystem Transitive: unsafe +47 58.9 MB dummdidumm
npm/svelte@3.59.1 None 0 10.6 MB conduitry
npm/tailwindcss@3.3.2 environment, filesystem +6 5.68 MB adamwathan
npm/typeforce@1.18.0 None 0 19.1 kB dcousens
npm/typescript@5.0.4 None 0 39.2 MB typescript-bot
npm/unplugin-icons@0.14.15 Transitive: environment +2 117 kB antfu
npm/util-deprecate@1.0.2 None 0 5.48 kB tootallnate
npm/util@0.12.5 environment +1 37.7 kB goto-bus-stop
npm/varint@5.0.0 None 0 9.03 kB chrisdickinson
npm/vite@4.5.0 environment, eval, filesystem, network, shell, unsafe +1 7 MB vitebot
npm/webextension-polyfill@0.10.0 None 0 198 kB addons-robot
npm/ws@8.5.0 network 0 131 kB lpinca
npm/xtend@4.0.2 None 0 6.46 kB raynos

🚮 Removed packages: npm/0xsequence@0.43.1, npm/@adraffy/ens-normalize@1.10.1, npm/@babel/code-frame@7.12.11, npm/@babel/compat-data@7.17.0, npm/@babel/core@7.23.2, npm/@babel/helper-annotate-as-pure@7.22.5, npm/@babel/helper-compilation-targets@7.22.15, npm/@babel/helper-create-class-features-plugin@7.22.15, npm/@babel/helper-define-polyfill-provider@0.3.1, npm/@babel/helper-plugin-utils@7.16.7, npm/@babel/helper-validator-option@7.22.15, npm/@babel/parser@7.23.0, npm/@babel/plugin-syntax-jsx@7.22.5, npm/@babel/plugin-syntax-typescript@7.22.5, npm/@babel/plugin-transform-modules-commonjs@7.23.0, npm/@babel/plugin-transform-runtime@7.17.0, npm/@babel/plugin-transform-typescript@7.22.15, npm/@babel/preset-typescript@7.23.2, npm/@babel/runtime@7.16.7, npm/@babel/traverse@7.23.2, npm/@babel/types@7.23.0, npm/@blocto/dappauth@2.1.0, npm/@blocto/sdk@0.4.9, npm/@cedelabs/providers@1.5.0, npm/@chainsafe/as-sha256@0.3.1, npm/@chainsafe/persistent-merkle-tree@0.4.2, npm/@chainsafe/ssz@0.9.4, npm/@chakra-ui/anatomy@1.3.0, npm/@chakra-ui/clickable@1.2.6, npm/@chakra-ui/color-mode@2.2.0, npm/@chakra-ui/focus-lock@1.2.6, npm/@chakra-ui/theme-tools@1.3.6, npm/@coinbase/wallet-sdk@3.7.2, npm/@cosmjs/crypto@0.31.3, npm/@cosmjs/encoding@0.31.3, npm/@cosmjs/math@0.31.3, npm/@cspotcode/source-map-consumer@0.8.0, npm/@cspotcode/source-map-support@0.7.0, npm/@discoveryjs/json-ext@0.5.6, npm/@emotion/react@11.11.4, npm/@emotion/serialize@1.1.3, npm/@esbuild/android-arm64@0.18.20, npm/@esbuild/android-arm@0.18.20, npm/@esbuild/android-x64@0.18.20, npm/@esbuild/darwin-arm64@0.18.20, npm/@esbuild/darwin-x64@0.18.20, npm/@esbuild/freebsd-arm64@0.18.20, npm/@esbuild/freebsd-x64@0.18.20, npm/@esbuild/linux-arm64@0.18.20, npm/@esbuild/linux-arm@0.18.20, npm/@esbuild/linux-ia32@0.18.20, npm/@esbuild/linux-loong64@0.18.20, npm/@esbuild/linux-mips64el@0.18.20, npm/@esbuild/linux-ppc64@0.18.20, npm/@esbuild/linux-riscv64@0.18.20, npm/@esbuild/linux-s390x@0.18.20, npm/@esbuild/linux-x64@0.18.20, npm/@esbuild/netbsd-x64@0.18.20, npm/@esbuild/openbsd-x64@0.18.20, npm/@esbuild/sunos-x64@0.18.20, npm/@esbuild/win32-arm64@0.18.20, npm/@esbuild/win32-ia32@0.18.20, npm/@esbuild/win32-x64@0.18.20, npm/@eslint/eslintrc@0.4.3, npm/@ethereumjs/common@2.5.0, npm/@ethereumjs/rlp@4.0.0, npm/@ethereumjs/tx@3.3.2, npm/@ethereumjs/util@8.0.2, npm/@ethersproject/abi@5.7.0, npm/@ethersproject/abstract-provider@5.7.0, npm/@ethersproject/abstract-signer@5.7.0, npm/@ethersproject/address@5.7.0, npm/@ethersproject/base64@5.7.0, npm/@ethersproject/basex@5.5.0, npm/@ethersproject/bignumber@5.7.0, npm/@ethersproject/bytes@5.7.0, npm/@ethersproject/constants@5.7.0, npm/@ethersproject/contracts@5.5.0, npm/@ethersproject/hash@5.7.0, npm/@ethersproject/hdnode@5.5.0, npm/@ethersproject/json-wallets@5.5.0, npm/@ethersproject/keccak256@5.7.0, npm/@ethersproject/networks@5.7.1, npm/@ethersproject/pbkdf2@5.5.0, npm/@ethersproject/properties@5.7.0, npm/@ethersproject/providers@5.5.0, npm/@ethersproject/random@5.5.1, npm/@ethersproject/rlp@5.7.0, npm/@ethersproject/sha2@5.5.0, npm/@ethersproject/signing-key@5.7.0, npm/@ethersproject/solidity@5.5.0, npm/@ethersproject/strings@5.7.0, npm/@ethersproject/transactions@5.7.0, npm/@ethersproject/units@5.5.0, npm/@ethersproject/wallet@5.5.0, npm/@ethersproject/web@5.7.1, npm/@ethersproject/wordlists@5.5.0, npm/@findeth/abi@0.3.1, npm/@formatjs/ecma402-abstract@1.11.3, npm/@formatjs/fast-memoize@1.2.1, npm/@formatjs/icu-messageformat-parser@2.0.18, npm/@hapi/address@5.1.1, npm/@hapi/tlds@1.0.1, npm/@hapi/topo@5.1.0, npm/@humanwhocodes/config-array@0.5.0, npm/@infinitywallet/infinity-connector@1.0.6, npm/@jridgewell/resolve-uri@3.1.1, npm/@jridgewell/trace-mapping@0.3.19, npm/@keepkey/device-protocol@7.7.0, npm/@keystonehq/base-eth-keyring@0.6.4, npm/@keystonehq/eth-keyring@0.14.4, npm/@ledgerhq/connect-kit-loader@1.1.0, npm/@ledgerhq/connect-kit@1.1.12, npm/@lit-labs/ssr-dom-shim@1.1.0, npm/@lit/reactive-element@1.6.1, npm/@magic-sdk/commons@4.1.0, npm/@magic-sdk/provider@26.0.0, npm/@magic-sdk/types@22.0.0, npm/@metamask/eth-json-rpc-middleware@11.0.0, npm/@metamask/eth-sig-util@5.1.0, npm/@metamask/onboarding@1.0.1, npm/@metamask/post-message-stream@6.2.0, npm/@metamask/providers@8.1.1, npm/@metamask/rpc-errors@5.1.1, npm/@metamask/sdk-communication-layer@0.13.0, npm/@metamask/sdk-install-modal-web@0.13.0, npm/@metamask/sdk@0.13.0, npm/@metamask/utils@3.6.0, npm/@motionone/animation@10.17.0, npm/@motionone/dom@10.12.0, npm/@motionone/easing@10.17.0, npm/@motionone/generators@10.17.0, npm/@motionone/svelte@10.16.2, npm/@motionone/utils@10.17.0, npm/@motionone/vue@10.16.2, npm/@myetherwallet/mewconnect-web-client@2.2.0-beta.16, npm/@ngraveio/bc-ur@1.1.6, npm/@niceties/logger@1.1.3, npm/@noble/ed25519@1.7.1, npm/@noble/secp256k1@1.6.3, npm/@nodelib/fs.scandir@2.1.5, npm/@nodelib/fs.walk@1.2.8, npm/@nothing-but/utils@0.3.2, npm/@parcel/watcher-android-arm64@2.3.0, npm/@parcel/watcher-darwin-arm64@2.3.0, npm/@parcel/watcher-darwin-x64@2.3.0, npm/@parcel/watcher-freebsd-x64@2.3.0, npm/@parcel/watcher-linux-arm-glibc@2.3.0, npm/@parcel/watcher-linux-arm64-glibc@2.3.0, npm/@parcel/watcher-linux-arm64-musl@2.3.0, npm/@parcel/watcher-linux-x64-glibc@2.3.0, npm/@parcel/watcher-linux-x64-musl@2.3.0, npm/@parcel/watcher-wasm@2.3.0, npm/@parcel/watcher-win32-arm64@2.3.0, npm/@parcel/watcher-win32-ia32@2.3.0, npm/@parcel/watcher-win32-x64@2.3.0, npm/@parcel/watcher@2.3.0, npm/@particle-network/analytics@1.0.1, npm/@particle-network/auth@1.3.1, npm/@particle-network/provider@1.3.2, npm/@portis/web3@4.0.7, npm/@rollup-extras/plugin-copy@1.2.2, npm/@rollup/plugin-json@4.1.0, npm/@rollup/plugin-node-resolve@11.2.1, npm/@rollup/plugin-replace@5.0.5, npm/@rollup/plugin-typescript@8.3.0, npm/@safe-global/safe-apps-provider@0.17.1, npm/@safe-global/safe-apps-sdk@8.0.0, npm/@shapeshiftoss/bitcoinjs-lib@5.2.0-shapeshift.2, npm/@shapeshiftoss/hdwallet-core@1.18.4, npm/@shapeshiftoss/hdwallet-keepkey-webusb@1.18.4, npm/@shapeshiftoss/hdwallet-keepkey@1.18.4, npm/@sideway/address@4.1.4, npm/@solana/web3.js@1.78.5, npm/@solid-devtools/debugger@0.22.4, npm/@solid-primitives/event-listener@2.3.0, npm/@solid-primitives/rootless@1.4.2, npm/@solid-primitives/utils@6.2.1, npm/@stablelib/binary@1.0.1, npm/@stablelib/chacha20poly1305@1.0.1, npm/@stablelib/ed25519@1.0.3, npm/@stablelib/hkdf@1.0.1, npm/@stablelib/keyagreement@1.0.1, npm/@stablelib/random@1.0.2, npm/@stablelib/sha256@1.0.1, npm/@stablelib/x25519@1.0.3, npm/@tanstack/query-persist-client-core@4.36.1, npm/@tanstack/query-sync-storage-persister@4.36.1, npm/@tanstack/react-query-persist-client@4.36.1, npm/@tanstack/react-query@4.36.1, npm/@toruslabs/base-controllers@2.8.0, npm/@toruslabs/http-helpers@3.3.0, npm/@toruslabs/openlogin-ed25519@3.2.0, npm/@toruslabs/openlogin-jrpc@3.2.0, npm/@toruslabs/openlogin@3.2.1, npm/@toruslabs/solana-embed@0.3.4, npm/@toruslabs/torus-embed@2.2.9, npm/@trezor/analytics@1.0.5, npm/@trezor/blockchain-link-types@1.0.4, npm/@trezor/blockchain-link-utils@1.0.5, npm/@trezor/blockchain-link@2.1.15, npm/@trezor/connect-analytics@1.0.4, npm/@trezor/connect-common@0.0.18, npm/@trezor/connect-web@9.1.1, npm/@tsconfig/node10@1.0.8, npm/@tsconfig/node12@1.0.9, npm/@tsconfig/node14@1.0.1, npm/@tsconfig/node16@1.0.2, npm/@tsconfig/svelte@2.0.1, npm/@types/body-parser@1.19.2, npm/@types/bonjour@3.5.10, npm/@types/connect-history-api-fallback@1.3.5, npm/@types/connect@3.4.35, npm/@types/eslint-scope@3.7.3, npm/@types/estree@1.0.5, npm/@types/express-serve-static-core@4.17.28, npm/@types/express@4.17.13, npm/@types/glob@7.2.0, npm/@types/http-proxy@1.17.8, npm/@types/istanbul-lib-coverage@2.0.4, npm/@types/json-schema@7.0.9, npm/@types/lodash.merge@4.6.6, npm/@types/lodash.partition@4.6.6, npm/@types/lodash.uniqby@4.7.6, npm/@types/lodash@4.14.178, npm/@types/prop-types@15.7.4, npm/@types/pug@2.0.6, npm/@types/react@18.0.9, npm/@types/retry@0.12.1, npm/@types/sass@1.43.1, npm/@types/secp256k1@4.0.3, npm/@types/serve-index@1.9.1, npm/@types/sockjs@0.3.33, npm/@types/trusted-types@2.0.3, npm/@types/use-sync-external-store@0.0.3, npm/@types/ws@7.4.7, npm/@typescript-eslint/eslint-plugin@4.33.0, npm/@typescript-eslint/parser@4.33.0, npm/@uauth/common@2.3.0, npm/@uauth/js@2.4.0, npm/@unstoppabledomains/resolution@8.3.3, npm/@venly/connect@2.2.0, npm/@venly/web3-provider@3.1.1, npm/@web3-onboard/coinbase@2.2.6, npm/css-loader@6.10.0, npm/style-loader@3.3.4, npm/webpack-cli@5.1.4, npm/webpack-dev-server@4.15.1

View full report↗︎

socket-security[bot] commented 6 months ago

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSource
Install scripts npm/svelte-preprocess@5.0.3
  • Install script: postinstall
  • Source: echo "[svelte-preprocess] Don't forget to install the preprocessors packages that will be used: sass, stylus, less, postcss & postcss-load-config, coffeescript, pug, etc..."
Install scripts npm/@sveltejs/kit@1.27.2
  • Install script: postinstall
  • Source: node postinstall.js

Ignoring: npm/bigint-buffer@1.1.5

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/svelte-preprocess@5.0.3
  • @SocketSecurity ignore npm/@sveltejs/kit@1.27.2
Adamj1232 commented 6 months ago

@SocketSecurity ignore npm/bigint-buffer@1.1.5 @SocketSecurity ignore npm/keccak@1.4.0 @SocketSecurity ignore npm/keccak@3.0.3 @SocketSecurity ignore npm/bufferutil@4.0.6 @SocketSecurity ignore npm/utf-8-validate@5.0.8 @SocketSecurity ignore npm/web3@1.10.0