Closed mixmix closed 1 year ago
New dependency changes detected. Learn more about Socket for GitHub ↗︎
🚨 Potential security issues found in this pull request. To accept the risk, merge this PR and you will not be notified again.
To ignore an alert, reply with a comment starting with @SocketSecurity ignore
followed by a space separated list of package-name@version
specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@*
or ignore all packages with @SocketSecurity ignore-all
@SocketSecurity ignore statistics@3.3.0
(Experimental) Package does not have a license and consumption legal status is unknown.
A new version of the package should be published that includes a valid SPDX license in a license file, package.json license field or mentioned in the README.
Package | Location | Source |
---|---|---|
statistics@3.3.0 (added) | Package overview | package.json via scuttle-testbot@2.1.0 |
Issue | Status |
---|---|
Install scripts | ✅ 0 issues |
Native code | ✅ 0 issues |
Bin script shell injection | ✅ 0 issues |
Unresolved require | ✅ 0 issues |
Invalid package.json | ✅ 0 issues |
HTTP dependency | ✅ 0 issues |
Git dependency | ✅ 0 issues |
Deprecated license | ✅ 0 issues |
Missing license | ⚠️ 1 issue |
Potential typo squat | ✅ 0 issues |
Known Malware | ✅ 0 issues |
Telemetry | ✅ 0 issues |
Protestware/Troll package | ✅ 0 issues |
📊 Modified Dependency Overview:
➕ Added Package | Capability Access | +/- Transitive Count |
Publisher |
---|---|---|---|
scuttle-testbot@2.1.0 | environment | +38 |
mixmix |
🚮 Removed packages: ssb-caps@1.1.0
changed this PR into another one, closing
Sidestep replication problems by allowing a fallback to "legacy" replication.