ever-co / ever-teams

Ever® Teams™ - Open Work and Project Management Platform - https://ever.team
https://ever.team
GNU Affero General Public License v3.0
264 stars 46 forks source link

[chore] added command build release server web #2664

Closed syns2191 closed 3 months ago

socket-security[bot] commented 3 months ago

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@babel/code-frame@7.22.13 None +1 33.1 kB nicolo-ribaudo
npm/@babel/compat-data@7.22.9 None 0 64.1 kB nicolo-ribaudo
npm/@babel/core@7.22.11 environment, filesystem, unsafe +3 1.45 MB nicolo-ribaudo
npm/@babel/generator@7.22.10 None +1 517 kB nicolo-ribaudo
npm/@babel/helper-compilation-targets@7.22.10 None +4 162 kB nicolo-ribaudo
npm/@babel/helper-create-class-features-plugin@7.22.11 None +7 306 kB nicolo-ribaudo
npm/@babel/helper-create-regexp-features-plugin@7.22.9 None +2 84.8 kB nicolo-ribaudo
npm/@babel/helper-module-transforms@7.22.9 None +4 234 kB nicolo-ribaudo
npm/@babel/helper-remap-async-to-generator@7.22.9 None +4 57.6 kB nicolo-ribaudo
npm/@babel/helper-replace-supers@7.22.9 None +3 103 kB nicolo-ribaudo
npm/@babel/helper-validator-identifier@7.22.5 None 0 49 kB nicolo-ribaudo
npm/@babel/highlight@7.22.13 Transitive: environment +2 55.1 kB nicolo-ribaudo
npm/@babel/parser@7.22.14 None 0 1.88 MB nicolo-ribaudo
npm/@babel/plugin-syntax-jsx@7.22.5 None 0 4.13 kB nicolo-ribaudo
npm/@babel/plugin-transform-optional-chaining@7.22.12 None +2 46.2 kB nicolo-ribaudo
npm/@babel/plugin-transform-parameters@7.22.5 None 0 64.9 kB nicolo-ribaudo
npm/@babel/plugin-transform-runtime@7.22.10 unsafe +5 1.05 MB nicolo-ribaudo
npm/@babel/preset-env@7.22.14 environment +81 2.48 MB nicolo-ribaudo
npm/@babel/preset-react@7.22.5 None +7 191 kB nicolo-ribaudo
npm/@babel/runtime@7.22.11 None +1 272 kB nicolo-ribaudo
npm/@babel/template@7.22.5 None 0 69 kB nicolo-ribaudo
npm/@babel/traverse@7.22.11 None +5 687 kB nicolo-ribaudo
npm/@babel/types@7.22.11 environment +2 2.43 MB nicolo-ribaudo
npm/@commitlint/cli@17.7.1 Transitive: filesystem +19 358 kB escapedcat
npm/@commitlint/config-conventional@17.7.0 Transitive: filesystem +1 25.5 kB escapedcat
npm/@commitlint/config-lerna-scopes@17.7.0 Transitive: environment, filesystem, unsafe +5 105 kB escapedcat
npm/@commitlint/load@17.7.1 environment +9 4 MB escapedcat
npm/@commitlint/travis-cli@17.7.1 None 0 9.42 kB escapedcat
npm/@compodoc/compodoc@1.1.21 Transitive: environment, eval, filesystem, network, shell, unsafe +36 71.1 MB compodoc
npm/@cucumber/cucumber-expressions@16.1.2 None +1 636 kB cukebot
npm/@cucumber/cucumber@8.11.1 environment, filesystem, network, shell, unsafe +37 11.5 MB cukebot
npm/@cucumber/gherkin@25.0.2 None +3 1.87 MB cukebot
npm/@cucumber/messages@21.0.1 None +3 1.33 MB cukebot
npm/@cypress/browserify-preprocessor@3.0.2 environment, filesystem Transitive: network, shell, unsafe +15 1.1 MB cypress-npm-publisher
npm/@jridgewell/gen-mapping@0.3.3 None +1 94.7 kB jridgewell
npm/@jridgewell/resolve-uri@3.1.1 None 0 55.2 kB jridgewell
npm/@jridgewell/trace-mapping@0.3.19 None 0 164 kB jridgewell
npm/@lerna/legacy-package-management@8.1.2 environment, filesystem, network Transitive: shell +27 1.28 MB jameshenry
npm/@lexical/react@0.8.1 None 0 337 kB thegreatercurve
npm/@next/eslint-plugin-next@13.4.19 filesystem Transitive: environment +3 153 kB vercel-release-bot
npm/@npmcli/arborist@7.2.2 environment, filesystem, network +1 476 kB gar
npm/@npmcli/run-script@7.0.2 environment, filesystem 0 18.5 kB npm-cli-ops
npm/@nx/cypress@16.7.4 None 0 205 kB nrwl-jason
npm/@nx/detox@16.7.4 None 0 65.5 kB nrwl-jason
npm/@nx/devkit@17.3.2 environment, filesystem, shell, unsafe 0 176 kB nrwl-jason
npm/@nx/eslint-plugin-nx@16.0.0-beta.1 filesystem 0 173 kB nrwl-jason
npm/@nx/jest@16.7.4 unsafe 0 156 kB nrwl-jason
npm/@nx/linter@16.7.4 shell 0 156 kB nrwl-jason
npm/@nx/nest@16.7.4 None 0 123 kB nrwl-jason
npm/@nx/next@16.7.4 environment, filesystem 0 248 kB nrwl-jason
npm/@nx/node@16.7.4 None 0 78.1 kB nrwl-jason
npm/@nx/react@16.7.4 None +1 561 kB nrwl-jason
npm/@nx/web@16.7.4 None 0 161 kB nrwl-jason
npm/@nx/webpack@16.7.4 environment, filesystem 0 169 kB nrwl-jason
npm/@nx/workspace@16.7.4 environment, filesystem 0 281 kB nrwl-jason
npm/@semantic-release/changelog@6.0.3 filesystem 0 10.6 kB semantic-release-bot
npm/@semantic-release/git@10.0.1 None 0 29.7 kB semantic-release-bot
npm/@semantic-release/github@9.2.6 network 0 75.5 kB semantic-release-bot
npm/@semantic-release/npm@11.0.3 filesystem +1 33 kB semantic-release-bot
npm/@types/detox@18.1.0 None 0 1.62 kB types
npm/@types/electron@1.6.10 None 0 1.73 kB types
npm/@types/yargs@17.0.32 None 0 60.2 kB types
npm/@typescript-eslint/eslint-plugin@5.60.1 None 0 2.42 MB jameshenry
npm/@typescript-eslint/parser@5.60.1 None 0 18.6 kB jameshenry
npm/ajv-formats@2.1.1 None 0 52.2 kB esp
npm/ajv@8.12.0 eval 0 1.02 MB esp
npm/ansi-colors@4.1.3 environment 0 26.1 kB jonschlinkert
npm/browserslist@4.21.10 environment, filesystem 0 61.9 kB ai
npm/cli-table3@0.6.3 None 0 51.8 kB speedytwenty
npm/cloc@2.0.0-cloc None 0 779 kB kentcdodds
npm/clone-deep@4.0.1 None 0 8 kB jonschlinkert
npm/cmd-shim@6.0.1 filesystem 0 11.8 kB nlf
npm/columnify@1.6.0 None 0 38.8 kB timoxley
npm/commander@10.0.1 environment, filesystem, shell 0 174 kB abetomo
npm/commitizen@4.3.0 eval Transitive: environment, filesystem +7 471 kB commitizen-bot
npm/concurrently@8.2.2 environment, filesystem +2 135 kB gustavohenke
npm/conventional-changelog-cli@2.2.2 None 0 34.7 kB oss-bot
npm/conventional-changelog@3.1.25 Transitive: filesystem, shell +4 124 kB oss-bot
npm/cosmiconfig@8.3.3 None 0 78.3 kB jrandolf
npm/cross-env@7.0.3 environment 0 29.1 kB kentcdodds
npm/cspell@8.0.0 environment, filesystem, network +1 402 kB jason-dent
npm/cypress-file-upload@5.0.8 None 0 200 kB abramenal
npm/cypress@11.2.0 environment, filesystem, shell, unsafe +4 5.49 MB cypress-npm-publisher
npm/cz-conventional-changelog@3.3.0 environment +1 39.7 kB commitizen-bot
npm/dedent@0.7.0 None 0 4.85 kB dmnd
npm/detox@20.11.1 environment, filesystem, shell, unsafe +3 8.33 MB wix.mobile
npm/envalid@6.0.2 environment, filesystem 0 28.2 kB af
npm/error-stack-parser@2.1.4 None 0 35.9 kB titanism
npm/eslint-config-prettier@8.10.0 None 0 19.9 kB lydell
npm/eslint-plugin-cypress@2.13.4 None +1 85.3 kB cypress-npm-publisher
npm/eslint-plugin-prettier@4.2.1 None 0 58.3 kB jounqin
npm/eslint-plugin-react@7.33.2 filesystem 0 795 kB ljharb
npm/eslint@8.46.0 environment, filesystem +3 3 MB eslintbot
npm/fast-glob@3.3.1 filesystem 0 96.7 kB mrmlnc
npm/faye-websocket@0.11.4 network 0 30.8 kB jcoglan
npm/figures@3.2.0 None 0 12.1 kB sindresorhus
npm/find-up@5.0.0 None 0 11.8 kB sindresorhus
npm/get-stream@6.0.0 None 0 12.3 kB sindresorhus
npm/git-raw-commits@2.0.11 shell 0 14.4 kB oss-bot
npm/graceful-fs@4.2.11 environment, filesystem 0 32.5 kB isaacs
npm/has-unicode@2.0.1 environment 0 3.44 kB iarna
npm/html-entities@2.4.0 None 0 96.5 kB mdevils
npm/husky@9.0.11 environment, filesystem, shell 0 3.61 kB typicode
npm/i18next@22.5.1 None 0 715 kB adrai
npm/inquirer@8.2.4 None 0 87.6 kB sboudrias
npm/is-ci@3.0.1 None 0 3.81 kB sibiraj-s
npm/is-installed-globally@0.4.0 filesystem 0 3.61 kB sindresorhus
npm/lerna-changelog@2.2.0 environment, network 0 60.7 kB turbo87
npm/lerna@8.1.2 Transitive: environment, filesystem, network, shell +21 5.16 MB jameshenry
npm/lexical@0.8.1 environment 0 495 kB thegreatercurve
npm/libnpmpublish@7.3.0 environment, filesystem +1 39.1 kB lukekarrys
npm/lint-staged@10.5.4 environment, filesystem +1 91.1 kB okonet
npm/load-json-file@6.2.0 None 0 5.59 kB sindresorhus
npm/loglevel@1.8.1 None 0 139 kB pimterry
npm/make-dir@4.0.0 filesystem 0 9.91 kB sindresorhus
npm/minimatch@9.0.3 environment 0 434 kB isaacs
npm/minimist@1.2.8 None 0 54.5 kB ljharb
npm/node-fetch@2.6.7 network 0 152 kB endless
npm/npm-registry-fetch@14.0.5 environment, filesystem, network +1 54.8 kB npm-cli-ops
npm/npmlog@6.0.2 None 0 17.1 kB lukekarrys
npm/nx-cloud@16.3.0 environment, filesystem, shell, unsafe 0 395 kB nrwlowner
npm/nx@16.7.4 environment, filesystem, network, shell, unsafe +5 2.82 MB nrwl-jason
npm/open@8.4.0 environment, filesystem, shell 0 46.4 kB sindresorhus
npm/pacote@17.0.6 environment, filesystem, network +4 175 kB npm-cli-ops
npm/path-scurry@1.10.1 filesystem +2 560 kB isaacs
npm/prettier-eslint-cli@8.0.1 Transitive: environment, filesystem +6 171 kB zimme
npm/pretty-format@29.4.3 None 0 60.2 kB simenb
npm/pretty-quick@4.0.0 filesystem 0 65.6 kB jounqin
npm/progress@2.0.3 None 0 15.5 kB turbopope
npm/read-cmd-shim@4.0.0 filesystem 0 5.16 kB lukekarrys
npm/read-package-json@6.0.4 filesystem Transitive: environment, shell, unsafe +3 405 kB npm-cli-ops
npm/resolve-global@1.0.0 None 0 4.34 kB sindresorhus
npm/rimraf@5.0.5 environment, filesystem +3 351 kB isaacs
npm/semantic-release@22.0.12 environment, network +2 736 kB semantic-release-bot
npm/send@0.18.0 filesystem, network 0 50.1 kB dougwilson
npm/simple-git@3.25.0 shell 0 955 kB steveukx
npm/source-map@0.7.4 filesystem, network 0 226 kB eemeli
npm/through2@2.0.5 None 0 9.65 kB rvagg
npm/tmp@0.2.1 filesystem 0 52.9 kB raszi
npm/traverse@0.6.7 None 0 75.9 kB ljharb
npm/ts-node@10.9.2 environment, filesystem, unsafe 0 757 kB blakeembrey
npm/uuid@9.0.0 None 0 123 kB ctavan
npm/xmlbuilder@15.1.1 None 0 321 kB oozcitak
npm/yargs@17.7.2 environment, filesystem 0 292 kB oss-bot

🚮 Removed packages: npm/@0no-co/graphql.web@1.0.4, npm/@ampproject/remapping@2.3.0, npm/@babel/code-frame@7.23.4, npm/@babel/code-frame@7.24.2, npm/@babel/compat-data@7.23.3, npm/@babel/core@7.22.9, npm/@babel/core@7.23.3, npm/@babel/generator@7.22.9, npm/@babel/generator@7.23.4, npm/@babel/helper-compilation-targets@7.22.15, npm/@babel/helper-compilation-targets@7.23.6, npm/@babel/helper-create-class-features-plugin@7.22.15, npm/@babel/helper-create-regexp-features-plugin@7.22.15, npm/@babel/helper-environment-visitor@7.22.20, npm/@babel/helper-function-name@7.23.0, npm/@babel/helper-module-transforms@7.23.3, npm/@babel/helper-remap-async-to-generator@7.22.20, npm/@babel/helper-replace-supers@7.22.20, npm/@babel/helper-string-parser@7.24.1, npm/@babel/helper-validator-identifier@7.22.20, npm/@babel/helpers@7.24.1, npm/@babel/highlight@7.23.4, npm/@babel/highlight@7.24.2, npm/@babel/parser@7.22.7, npm/@babel/parser@7.23.4, npm/@babel/plugin-proposal-decorators@7.21.0, npm/@babel/plugin-proposal-nullish-coalescing-operator@7.18.6, npm/@babel/plugin-proposal-optional-catch-binding@7.18.6, npm/@babel/plugin-proposal-optional-chaining@7.21.0, npm/@babel/plugin-syntax-decorators@7.23.3, npm/@babel/plugin-syntax-export-default-from@7.23.3, npm/@babel/plugin-syntax-flow@7.23.3, npm/@babel/plugin-syntax-jsx@7.23.3, npm/@babel/plugin-syntax-typescript@7.23.3, npm/@babel/plugin-transform-arrow-functions@7.23.3, npm/@babel/plugin-transform-async-to-generator@7.23.3, npm/@babel/plugin-transform-block-scoped-functions@7.23.3, npm/@babel/plugin-transform-block-scoping@7.23.4, npm/@babel/plugin-transform-classes@7.23.3, npm/@babel/plugin-transform-computed-properties@7.23.3, npm/@babel/plugin-transform-destructuring@7.23.3, npm/@babel/plugin-transform-flow-strip-types@7.24.7, npm/@babel/plugin-transform-for-of@7.23.3, npm/@babel/plugin-transform-function-name@7.23.3, npm/@babel/plugin-transform-literals@7.23.3, npm/@babel/plugin-transform-member-expression-literals@7.23.3, npm/@babel/plugin-transform-modules-commonjs@7.23.3, npm/@babel/plugin-transform-object-super@7.23.3, npm/@babel/plugin-transform-parameters@7.23.3, npm/@babel/plugin-transform-property-literals@7.23.3, npm/@babel/plugin-transform-react-jsx@7.23.4, npm/@babel/plugin-transform-shorthand-properties@7.23.3, npm/@babel/plugin-transform-spread@7.23.3, npm/@babel/plugin-transform-sticky-regex@7.23.3, npm/@babel/plugin-transform-template-literals@7.23.3, npm/@babel/plugin-transform-typescript@7.23.4, npm/@babel/plugin-transform-unicode-regex@7.23.3, npm/@babel/preset-env@7.23.3, npm/@babel/preset-typescript@7.23.3, npm/@babel/runtime@7.23.4, npm/@babel/template@7.22.15, npm/@babel/template@7.24.0, npm/@babel/traverse@7.22.8, npm/@babel/traverse@7.23.4, npm/@babel/types@7.22.5, npm/@babel/types@7.23.4, npm/@eslint-community/regexpp@4.10.0, npm/@expo-google-fonts/space-grotesk@0.2.3, npm/@expo/bunyan@4.0.0, npm/@expo/config-plugins@6.0.2, npm/@expo/json-file@8.2.37, npm/@jridgewell/gen-mapping@0.3.5, npm/@jridgewell/resolve-uri@3.1.2, npm/@jridgewell/set-array@1.2.1, npm/@jridgewell/sourcemap-codec@1.4.14, npm/@jridgewell/trace-mapping@0.3.25, npm/@lezer/common@0.15.12, npm/@mischnic/json-sourcemap@0.1.0, npm/@nodelib/fs.stat@2.0.5, npm/@parcel/source-map@2.1.1, npm/@parcel/watcher@2.2.0, npm/@plasmohq/prettier-plugin-sort-imports@4.0.1, npm/@svgr/plugin-jsx@6.5.1, npm/@swc/counter@0.1.3, npm/@swc/types@0.1.6, npm/@tailwindcss/forms@0.5.3, npm/@tailwindcss/typography@0.5.8, npm/@types/chrome@0.0.203, npm/@types/estree@1.0.5, npm/@types/http-cache-semantics@4.0.4, npm/@types/react-dom@18.0.6, npm/@types/react@18.0.21, npm/abortcontroller-polyfill@1.7.5, npm/acorn@8.11.3, npm/bare-events@2.2.2, npm/bare-os@2.2.1, npm/bare-path@2.1.0, npm/bl@4.1.0, npm/braces@3.0.3, npm/browserslist@4.23.0, npm/cacheable-request@10.2.14, npm/caniuse-lite@1.0.30001603, npm/classnames@2.5.1, npm/color-name@1.1.3, npm/csstype@3.1.1, npm/domelementtype@2.3.0, npm/electron-to-chromium@1.4.722, npm/end-of-stream@1.4.4, npm/fast-fifo@1.3.2, npm/get-intrinsic@1.2.4, npm/get-stream@6.0.1, npm/graceful-fs@4.2.10, npm/ieee754@1.2.1, npm/ignore@5.2.4, npm/is-glob@4.0.3, npm/is-reference@3.0.2, npm/keyv@4.5.4, npm/lilconfig@2.0.6, npm/merge2@1.4.1, npm/micromatch@4.0.5, npm/minimist@1.2.7, npm/mkdirp-classic@0.5.3, npm/msgpackr-extract@3.0.2, npm/node-addon-api@7.1.0, npm/node-gyp-build@4.5.0, npm/node-releases@2.0.14, npm/normalize-path@3.0.0, npm/nullthrows@1.1.1, npm/onetime@5.1.2, npm/ordered-binary@1.4.0, npm/plasmo@0.85.2, npm/postcss-selector-parser@6.0.10, npm/postcss-value-parser@4.2.0, npm/postcss@8.4.31, npm/posthtml@0.16.6, npm/rc@1.2.8, npm/react-dom@18.2.0, npm/react-timer-hook@3.0.5, npm/react@18.2.0, npm/readable-stream@3.6.0, npm/resolve@1.22.1, npm/safer-buffer@2.1.2, npm/simple-get@4.0.1, npm/source-map-js@1.0.2, npm/streamx@2.16.1, npm/string-width@4.2.3, npm/svgo@2.8.0, npm/tailwindcss@3.2.4, npm/tslib@2.4.1, npm/typescript@4.9.5, npm/update-browserslist-db@1.0.13, npm/util-deprecate@1.0.2

View full report↗︎

socket-security[bot] commented 3 months ago

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSourceCI
Install scripts npm/cypress@11.2.0
  • Install script: postinstall
  • Source: node index.js --exec install
🚫
Install scripts npm/@compodoc/compodoc@1.1.21
  • Install script: postinstall
  • Source: opencollective-postinstall || exit 0
🚫
Install scripts npm/detox@20.11.1
  • Install script: postinstall
  • Source: node scripts/postinstall.js
🚫
Install scripts npm/nx@16.7.4
  • Install script: postinstall
  • Source: node ./bin/post-install
🚫

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/cypress@11.2.0
  • @SocketSecurity ignore npm/@compodoc/compodoc@1.1.21
  • @SocketSecurity ignore npm/detox@20.11.1
  • @SocketSecurity ignore npm/nx@16.7.4