Closed ppacher closed 8 months ago
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎
To accept the risk, merge this PR and you will not be notified again.
Alert | Package | Note | Source |
---|---|---|---|
Install scripts | npm/@fortawesome/free-solid-svg-icons@6.4.0 |
| |
Install scripts | npm/@fortawesome/fontawesome-svg-core@6.4.0 |
| |
Install scripts | npm/@fortawesome/free-regular-svg-icons@6.4.0 |
| |
Install scripts | npm/esbuild@0.17.18 |
| |
Install scripts | npm/@fortawesome/fontawesome-common-types@6.4.0 |
| |
Install scripts | npm/@fortawesome/free-brands-svg-icons@6.4.0 |
|
Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.
Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.
Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.
If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.
To ignore an alert, reply with a comment starting with @SocketSecurity ignore
followed by a space separated list of ecosystem/package-name@version
specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0
or ignore all packages with @SocketSecurity ignore-all
@SocketSecurity ignore npm/@fortawesome/free-solid-svg-icons@6.4.0
@SocketSecurity ignore npm/@fortawesome/fontawesome-svg-core@6.4.0
@SocketSecurity ignore npm/@fortawesome/free-regular-svg-icons@6.4.0
@SocketSecurity ignore npm/esbuild@0.17.18
@SocketSecurity ignore npm/@fortawesome/fontawesome-common-types@6.4.0
@SocketSecurity ignore npm/@fortawesome/free-brands-svg-icons@6.4.0
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: npm/@babel/code-frame@7.8.3, npm/@babel/compat-data@7.10.1, npm/@babel/core@7.10.2, npm/@babel/generator@7.9.5, npm/@babel/helper-annotate-as-pure@7.10.1, npm/@babel/helper-builder-binary-assignment-operator-visitor@7.10.1, npm/@babel/helper-compilation-targets@7.10.2, npm/@babel/helper-create-class-features-plugin@7.10.2, npm/@babel/helper-create-regexp-features-plugin@7.10.1, npm/@babel/helper-define-map@7.10.1, npm/@babel/helper-explode-assignable-expression@7.10.1, npm/@babel/helper-function-name@7.9.5, npm/@babel/helper-get-function-arity@7.8.3, npm/@babel/helper-hoist-variables@7.10.1, npm/@babel/helper-member-expression-to-functions@7.10.1, npm/@babel/helper-module-imports@7.10.1, npm/@babel/helper-module-transforms@7.10.1, npm/@babel/helper-optimise-call-expression@7.10.1, npm/@babel/helper-plugin-utils@7.10.1, npm/@babel/helper-regex@7.10.1, npm/@babel/helper-remap-async-to-generator@7.10.1, npm/@babel/helper-replace-supers@7.10.1, npm/@babel/helper-simple-access@7.10.1, npm/@babel/helper-split-export-declaration@7.8.3, npm/@babel/helper-validator-identifier@7.9.5, npm/@babel/helper-wrap-function@7.10.1, npm/@babel/helpers@7.10.1, npm/@babel/highlight@7.9.0, npm/@babel/parser@7.9.4, npm/@babel/plugin-proposal-async-generator-functions@7.10.1, npm/@babel/plugin-proposal-class-properties@7.10.1, npm/@babel/plugin-proposal-decorators@7.10.1, npm/@babel/plugin-proposal-dynamic-import@7.10.1, npm/@babel/plugin-proposal-json-strings@7.10.1, npm/@babel/plugin-proposal-nullish-coalescing-operator@7.10.1, npm/@babel/plugin-proposal-numeric-separator@7.10.1, npm/@babel/plugin-proposal-object-rest-spread@7.10.1, npm/@babel/plugin-proposal-optional-catch-binding@7.10.1, npm/@babel/plugin-proposal-optional-chaining@7.10.1, npm/@babel/plugin-proposal-private-methods@7.10.1, npm/@babel/plugin-proposal-unicode-property-regex@7.10.1, npm/@babel/plugin-syntax-class-properties@7.10.1, npm/@babel/plugin-syntax-decorators@7.10.1, npm/@babel/plugin-syntax-jsx@7.10.1, npm/@babel/plugin-syntax-numeric-separator@7.10.1, npm/@babel/plugin-syntax-top-level-await@7.10.1, npm/@babel/plugin-transform-arrow-functions@7.10.1, npm/@babel/plugin-transform-async-to-generator@7.10.1, npm/@babel/plugin-transform-block-scoped-functions@7.10.1, npm/@babel/plugin-transform-block-scoping@7.10.1, npm/@babel/plugin-transform-classes@7.10.1, npm/@babel/plugin-transform-computed-properties@7.10.1, npm/@babel/plugin-transform-destructuring@7.10.1, npm/@babel/plugin-transform-dotall-regex@7.10.1, npm/@babel/plugin-transform-duplicate-keys@7.10.1, npm/@babel/plugin-transform-exponentiation-operator@7.10.1, npm/@babel/plugin-transform-for-of@7.10.1, npm/@babel/plugin-transform-function-name@7.10.1, npm/@babel/plugin-transform-literals@7.10.1, npm/@babel/plugin-transform-member-expression-literals@7.10.1, npm/@babel/plugin-transform-modules-amd@7.10.1, npm/@babel/plugin-transform-modules-commonjs@7.10.1, npm/@babel/plugin-transform-modules-systemjs@7.10.1, npm/@babel/plugin-transform-modules-umd@7.10.1, npm/@babel/plugin-transform-named-capturing-groups-regex@7.8.3, npm/@babel/plugin-transform-new-target@7.10.1, npm/@babel/plugin-transform-object-super@7.10.1, npm/@babel/plugin-transform-parameters@7.10.1, npm/@babel/plugin-transform-property-literals@7.10.1, npm/@babel/plugin-transform-regenerator@7.10.1, npm/@babel/plugin-transform-reserved-words@7.10.1, npm/@babel/plugin-transform-runtime@7.10.1, npm/@babel/plugin-transform-shorthand-properties@7.10.1, npm/@babel/plugin-transform-spread@7.10.1, npm/@babel/plugin-transform-sticky-regex@7.10.1, npm/@babel/plugin-transform-template-literals@7.10.1, npm/@babel/plugin-transform-typeof-symbol@7.10.1, npm/@babel/plugin-transform-unicode-escapes@7.10.1, npm/@babel/plugin-transform-unicode-regex@7.10.1, npm/@babel/preset-env@7.10.2, npm/@babel/preset-modules@0.1.3, npm/@babel/runtime@7.10.2, npm/@babel/template@7.8.6, npm/@babel/traverse@7.9.5, npm/@babel/types@7.9.5, npm/@hapi/address@2.1.4, npm/@hapi/bourne@1.3.2, npm/@hapi/hoek@8.5.1, npm/@hapi/joi@15.1.1, npm/@hapi/topo@3.1.6, npm/@intervolga/optimize-cssnano-plugin@1.0.6, npm/@mrmlnc/readdir-enhanced@2.2.1, npm/@nodelib/fs.stat@1.1.3, npm/@soda/friendly-errors-webpack-plugin@1.7.1, npm/@soda/get-current-script@1.0.1, npm/@types/color-name@1.1.1, npm/@types/glob@7.1.2, npm/@types/json-schema@7.0.5, npm/@types/minimatch@3.0.3, npm/@types/node@14.0.13, npm/@types/normalize-package-data@2.4.0, npm/@types/q@1.5.4, npm/@vue/babel-helper-vue-jsx-merge-props@1.0.0, npm/@vue/babel-plugin-transform-vue-jsx@1.1.2, npm/@vue/babel-preset-app@4.4.4, npm/@vue/babel-preset-jsx@1.1.2, npm/@vue/babel-sugar-functional-vue@1.1.2, npm/@vue/babel-sugar-inject-h@1.1.2, npm/@vue/babel-sugar-v-model@1.1.2, npm/@vue/babel-sugar-v-on@1.1.2, npm/@vue/cli-overlay@4.4.4, npm/@vue/cli-plugin-babel@4.4.4, npm/@vue/cli-plugin-eslint@4.4.4, npm/@vue/cli-plugin-router@4.4.4, npm/@vue/cli-plugin-vuex@4.4.4, npm/@vue/cli-service@4.4.4, npm/@vue/cli-shared-utils@4.4.4, npm/@vue/component-compiler-utils@3.1.2, npm/@vue/eslint-config-prettier@6.0.0, npm/@vue/preload-webpack-plugin@1.1.1, npm/@vue/web-component-wrapper@1.2.0, npm/@webassemblyjs/ast@1.9.0, npm/@webassemblyjs/floating-point-hex-parser@1.9.0, npm/@webassemblyjs/helper-api-error@1.9.0, npm/@webassemblyjs/helper-buffer@1.9.0, npm/@webassemblyjs/helper-code-frame@1.9.0, npm/@webassemblyjs/helper-fsm@1.9.0, npm/@webassemblyjs/helper-module-context@1.9.0, npm/@webassemblyjs/helper-wasm-bytecode@1.9.0, npm/@webassemblyjs/helper-wasm-section@1.9.0, npm/@webassemblyjs/ieee754@1.9.0, npm/@webassemblyjs/leb128@1.9.0, npm/@webassemblyjs/utf8@1.9.0, npm/@webassemblyjs/wasm-edit@1.9.0, npm/@webassemblyjs/wasm-gen@1.9.0, npm/@webassemblyjs/wasm-opt@1.9.0, npm/@webassemblyjs/wasm-parser@1.9.0, npm/@webassemblyjs/wast-parser@1.9.0, npm/@webassemblyjs/wast-printer@1.9.0, npm/accepts@1.3.7, npm/acorn-jsx@5.2.0, npm/acorn-walk@7.1.1, npm/acorn@6.4.1, npm/address@1.1.2, npm/aggregate-error@3.0.1, npm/ajv-errors@1.0.1, npm/ajv-keywords@3.4.1, npm/ajv@6.12.0, npm/alphanum-sort@1.0.2, npm/amdefine@1.0.1, npm/ansi-colors@3.2.4, npm/ansi-escapes@4.3.1, npm/ansi-html@0.0.7, npm/ansi-regex@4.1.0, npm/anymatch@3.1.1, npm/aproba@1.2.0, npm/arch@2.1.2, npm/are-we-there-yet@1.1.5, npm/arr-diff@4.0.0, npm/arr-flatten@1.1.0, npm/arr-union@3.1.0, npm/array-find-index@1.0.2, npm/array-unique@0.3.2, npm/asn1.js@4.10.1, npm/asn1@0.2.4, npm/assert@1.5.0, npm/assign-symbols@1.0.0, npm/astral-regex@1.0.0, npm/async-each@1.0.3, npm/async-foreach@0.1.3, npm/async-limiter@1.0.1, npm/async@2.6.3, npm/atob@2.1.2, npm/autoprefixer@9.8.0, npm/aws4@1.10.0, npm/babel-eslint@10.1.0, npm/babel-loader@8.1.0, npm/babel-plugin-dynamic-import-node@2.3.3, npm/balanced-match@1.0.0, npm/base64-js@1.3.1, npm/base@0.11.2, npm/bfj@6.1.2, npm/binary-extensions@2.0.0, npm/block-stream@0.0.9, npm/bluebird@3.7.2, npm/bn.js@5.1.2, npm/body-parser@1.19.0, npm/bonjour@3.5.0, npm/braces@2.3.2, npm/brorand@1.1.0, npm/browserify-aes@1.2.0, npm/browserify-cipher@1.0.1, npm/browserify-des@1.0.2, npm/browserify-rsa@4.0.1, npm/browserify-sign@4.2.0, npm/browserify-zlib@0.2.0, npm/browserslist@4.12.0, npm/buffer-from@1.1.1, npm/buffer-indexof@1.1.1, npm/buffer-json@2.0.0, npm/buffer-xor@1.0.3, npm/buffer@4.9.2, npm/builtin-status-codes@3.0.0, npm/bytes@3.1.0, npm/cacache@12.0.4, npm/cache-base@1.0.1, npm/cache-loader@4.1.0, npm/call-me-maybe@1.0.1, npm/caller-callsite@2.0.0, npm/caller-path@2.0.0, npm/callsites@2.0.0, npm/camel-case@3.0.0, npm/camelcase-keys@2.1.0, npm/caniuse-api@3.0.0, npm/caniuse-lite@1.0.30001083, npm/case-sensitive-paths-webpack-plugin@2.3.0, npm/check-types@8.0.3, npm/chokidar@3.4.0, npm/chownr@1.1.4, npm/chrome-trace-event@1.0.2, npm/ci-info@1.6.0, npm/cipher-base@1.0.4, npm/class-utils@0.3.6, npm/clean-css@4.2.3, npm/cli-cursor@2.1.0, npm/cli-highlight@2.1.4, npm/cli-spinners@2.3.0, npm/cli-width@2.2.1, npm/clipboardy@2.3.0, npm/cliui@6.0.0, npm/coa@2.0.2, npm/code-point-at@1.1.0, npm/collection-visit@1.0.0, npm/color-string@1.5.3, npm/color@3.1.2, npm/component-emitter@1.3.0, npm/concat-stream@1.6.2, npm/connect-history-api-fallback@1.6.0, npm/console-browserify@1.2.0, npm/consolidate@0.15.1, npm/constants-browserify@1.0.0, npm/content-disposition@0.5.3, npm/convert-source-map@1.7.0, npm/cookie@0.4.0, npm/copy-concurrently@1.0.5, npm/copy-descriptor@0.1.1, npm/copy-webpack-plugin@5.1.1, npm/core-js-compat@3.6.5, npm/core-js@3.6.5, npm/cosmiconfig@5.2.1, npm/create-ecdh@4.0.3, npm/create-hash@1.2.0, npm/create-hmac@1.1.7, npm/cross-spawn@6.0.5, npm/crypto-browserify@3.12.0, npm/css-color-names@0.0.4, npm/css-declaration-sorter@4.0.1, npm/css-loader@3.6.0, npm/css-select-base-adapter@0.1.1, npm/css-select@2.1.0, npm/css-tree@1.0.0-alpha.37, npm/css-what@3.3.0, npm/cssnano-preset-default@4.0.7, npm/cssnano-util-get-arguments@4.0.0, npm/cssnano-util-get-match@4.0.0, npm/cssnano-util-raw-cache@4.0.1, npm/cssnano-util-same-parent@4.0.1, npm/cssnano@4.1.10, npm/csso@4.0.3, npm/currently-unhandled@0.4.1, npm/cyclist@1.0.1, npm/de-indent@1.0.2, npm/debug@4.1.1, npm/decode-uri-component@0.2.0, npm/deep-equal@1.1.1, npm/deep-is@0.1.3, npm/deepmerge@1.5.2, npm/default-gateway@5.0.5, npm/define-properties@1.1.3, npm/define-property@2.0.2, npm/depd@1.1.2, npm/des.js@1.0.1, npm/destroy@1.0.4, npm/detect-node@2.0.4, npm/diffie-hellman@5.0.3, npm/dir-glob@2.2.2, npm/dns-packet@1.3.1, npm/dns-txt@2.0.2, npm/dom-converter@0.2.0, npm/dom-serializer@0.2.2, npm/domain-browser@1.2.0, npm/domelementtype@1.3.1, npm/domhandler@2.4.2, npm/domutils@1.7.0, npm/dot-prop@5.2.0, npm/dotenv-expand@5.1.0, npm/dotenv@8.2.0, npm/duplexer@0.1.1, npm/duplexify@3.7.1, npm/easy-stack@1.0.0, npm/ejs@2.7.4, npm/electron-to-chromium@1.3.473, npm/elliptic@6.5.2, npm/enhanced-resolve@4.1.1, npm/entities@2.0.3, npm/errno@0.1.7, npm/error-stack-parser@2.0.6, npm/es-abstract@1.17.6, npm/eslint-config-prettier@6.10.1, npm/eslint-loader@2.2.1, npm/eslint-plugin-prettier@3.1.4, npm/eslint-plugin-vue@6.2.2, npm/eslint-scope@4.0.3, npm/eslint-utils@1.4.3, npm/eslint-visitor-keys@1.1.0, npm/eslint@6.8.0, npm/espree@6.2.1, npm/esquery@1.3.1, npm/esrecurse@4.2.1, npm/event-pubsub@4.3.0, npm/eventemitter3@4.0.4, npm/events@3.1.0, npm/eventsource@1.0.7, npm/evp_bytestokey@1.0.3, npm/execa@1.0.0, npm/expand-brackets@2.1.4, npm/express@4.17.1, npm/extend-shallow@3.0.2, npm/extglob@2.0.4, npm/fast-deep-equal@3.1.1, npm/fast-diff@1.2.0, npm/fast-glob@2.2.7, npm/faye-websocket@0.10.0, npm/figgy-pudding@3.5.2, npm/file-entry-cache@5.0.1, npm/file-loader@4.3.0, npm/filesize@3.6.1, npm/fill-range@4.0.0, npm/find-cache-dir@2.1.0, npm/find-up@2.1.0, npm/flat-cache@2.0.1, npm/flatted@2.0.2, npm/flush-write-stream@1.1.1, npm/follow-redirects@1.11.0, npm/for-in@1.0.2, npm/forwarded@0.1.2, npm/fragment-cache@0.2.1, npm/from2@2.3.0, npm/fs-extra@7.0.1, npm/fs-minipass@2.1.0, npm/fs-write-stream-atomic@1.0.10, npm/fsevents@2.1.3, npm/fstream@1.0.12, npm/function-bind@1.1.1, npm/functional-red-black-tree@1.0.1, npm/gauge@2.7.4, npm/gaze@1.1.3, npm/gensync@1.0.0-beta.1, npm/get-stdin@6.0.0, npm/get-stream@4.1.0, npm/get-value@2.0.6, npm/glob-to-regexp@0.3.0, npm/glob@7.1.6, npm/globby@9.2.0, npm/globule@1.3.2, npm/graceful-fs@4.2.4, npm/gzip-size@5.1.1, npm/har-validator@5.1.3, npm/has-symbols@1.0.1, npm/has-value@1.0.0, npm/has-values@1.0.0, npm/hash-base@3.1.0, npm/hash-sum@2.0.0, npm/hash.js@1.1.7, npm/he@1.2.0, npm/hex-color-regex@1.1.0, npm/highlight.js@9.18.1, npm/hmac-drbg@1.0.1, npm/hoopy@0.1.4, npm/hosted-git-info@2.8.8, npm/hsl-regex@1.0.0, npm/hsla-regex@1.0.0, npm/html-comment-regex@1.1.2, npm/html-entities@1.3.1, npm/html-minifier@3.5.21, npm/html-tags@2.0.0, npm/html-webpack-plugin@3.2.0, npm/htmlparser2@3.10.1, npm/http-errors@1.7.2, npm/http-proxy-middleware@0.19.1, npm/https-browserify@1.0.0, npm/human-signals@1.1.1, npm/icss-utils@4.1.1, npm/ieee754@1.1.13, npm/iferr@0.1.5, npm/ignore@4.0.6, npm/import-cwd@2.1.0, npm/import-fresh@2.0.0, npm/import-from@2.1.0, npm/import-local@2.0.0, npm/in-publish@2.0.1, npm/indexes-of@1.0.1, npm/inquirer@7.1.0, npm/internal-ip@4.3.0, npm/invariant@2.2.4, npm/ip-regex@2.1.0, npm/ip@1.1.5, npm/ipaddr.js@1.9.1, npm/is-absolute-url@2.1.0, npm/is-accessor-descriptor@0.1.6, npm/is-arguments@1.0.4, npm/is-buffer@1.1.6, npm/is-callable@1.2.0, npm/is-ci@1.2.1, npm/is-color-stop@1.1.0, npm/is-data-descriptor@0.1.4, npm/is-date-object@1.0.2, npm/is-descriptor@0.1.6, npm/is-directory@0.3.1, npm/is-docker@2.0.0, npm/is-extendable@0.1.1, npm/is-finite@1.1.0, npm/is-glob@4.0.1, npm/is-number@3.0.0, npm/is-obj@2.0.0, npm/is-plain-obj@1.1.0, npm/is-promise@2.1.0, npm/is-regex@1.1.0, npm/is-resolvable@1.1.0, npm/is-stream@1.1.0, npm/is-svg@3.0.0, npm/is-symbol@1.0.3, npm/is-utf8@0.2.1, npm/is-windows@1.0.2, npm/is-wsl@1.1.0, npm/javascript-stringify@2.0.1, npm/jest-worker@25.5.0, npm/jquery@3.5.1, npm/js-base64@2.5.2, npm/js-message@1.0.5, npm/js-queue@2.0.0, npm/js-yaml@3.13.1, npm/json-schema@0.2.3, npm/json-stable-stringify-without-jsonify@1.0.1, npm/json-stringify-safe@5.0.1, npm/json3@3.3.3, npm/json5@2.1.3, npm/jsonfile@4.0.0, npm/jsprim@1.4.1, npm/killable@1.0.1, npm/kind-of@6.0.3, npm/launch-editor-middleware@2.2.1, npm/launch-editor@2.2.1, npm/leven@3.1.0, npm/levenary@1.1.1, npm/levn@0.3.0, npm/lines-and-columns@1.1.6, npm/load-json-file@1.1.0, npm/loader-fs-cache@1.0.3, npm/loader-runner@2.4.0, npm/loader-utils@1.4.0, npm/locate-path@2.0.0, npm/lodash.defaultsdeep@4.6.1, npm/lodash.kebabcase@4.1.1, npm/lodash.mapvalues@4.6.0, npm/lodash.memoize@4.1.2, npm/lodash.transform@4.6.0, npm/lodash.uniq@4.5.0, npm/lodash@4.17.15, npm/log-symbols@2.2.0, npm/loglevel@1.6.8, npm/loose-envify@1.4.0, npm/loud-rejection@1.6.0, npm/lower-case@1.1.4, npm/make-dir@2.1.0, npm/map-cache@0.2.2, npm/map-obj@1.0.1, npm/map-visit@1.0.0, npm/md5.js@1.3.5, npm/mdn-data@2.0.4, npm/media-typer@0.3.0, npm/memory-fs@0.4.1, npm/meow@3.7.0, npm/merge-descriptors@1.0.1, npm/merge-source-map@1.1.0, npm/merge-stream@2.0.0, npm/merge2@1.4.1, npm/methods@1.1.2, npm/micromatch@3.1.10, npm/miller-rabin@4.0.1, npm/mime-db@1.44.0, npm/mime-types@2.1.27, npm/mime@2.4.6, npm/mimic-fn@1.2.0, npm/mini-css-extract-plugin@0.9.0, npm/minimalistic-assert@1.0.1, npm/minimalistic-crypto-utils@1.0.1, npm/minimatch@3.0.4, npm/minimist@1.2.5, npm/minipass-collect@1.0.2, npm/minipass-flush@1.0.5, npm/minipass-pipeline@1.2.3, npm/minipass@3.1.3, npm/mississippi@3.0.0, npm/mixin-deep@1.3.2, npm/mkdirp@0.5.5, npm/move-concurrently@1.0.1, npm/ms@2.1.2, npm/multicast-dns-service-types@1.1.0, npm/multicast-dns@6.2.3, npm/mute-stream@0.0.8, npm/mz@2.7.0, npm/nan@2.14.1, npm/nanomatch@1.2.13, npm/natural-compare@1.4.0, npm/negotiator@0.6.2, npm/neo-async@2.6.1, npm/nice-try@1.0.5, npm/no-case@2.3.2, npm/node-forge@0.9.0, npm/node-gyp@3.8.0, npm/node-ipc@9.1.1, npm/node-libs-browser@2.2.1, npm/node-releases@1.1.58, npm/node-sass@4.14.1, npm/nopt@3.0.6, npm/normalize-package-data@2.5.0, npm/normalize-path@3.0.0, npm/normalize-range@0.1.2, npm/normalize-url@3.3.0, npm/npm-run-path@2.0.2, npm/npmlog@4.1.2, npm/nth-check@1.0.2, npm/num2fraction@1.2.2, npm/number-is-nan@1.0.1, npm/oauth-sign@0.9.0, npm/object-assign@4.1.1, npm/object-copy@0.1.0