Bumps the major group with 3 updates in the /@shared/api directory: prettier, typescript and @lavamoat/allow-scripts.
Bumps the major group with 1 update in the /@shared/helpers directory: typescript.
Bumps the major group with 1 update in the /@stellar/freighter-api directory: @lavamoat/allow-scripts.
Bumps the major group with 23 updates in the /extension directory:
The maintainer of the package marked it as deprecated. This could indicate that a single version should not be used, or that the package is no longer maintained and any new vulnerabilities will not be fixed.
Research the state of the package and determine if there are non-deprecated versions that can be used, or if it should be replaced with a new, supported solution.
Take a deeper look at the dependency
Take a moment to review the security alert above. Review the linked
package source code to understand the potential risk. Ensure the package
is not malicious before proceeding. If you're unsure how to proceed, reach
out to your security team or ask the Socket team for help at support [AT]
socket [DOT] dev.
Remove the package
If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.
Mark a package as acceptable risk
To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all
Bumps the major group with 47 updates in the / directory:
7.31.2
10.4.0
4.2.4
6.6.3
5.14.9
6.0.0
5.62.0
8.14.0
5.62.0
8.14.0
8.57.0
9.15.0
6.15.0
9.1.0
2.7.1
3.6.3
4.7.0
8.0.3
4.6.2
5.0.0
9.3.5
11.0.0
11.8.5
14.4.4
8.0.3
9.1.6
3.1.0
4.0.2
28.1.3
29.7.0
24.9.1
29.5.14
16.7.0
25.0.1
10.5.4
15.2.10
2.8.8
3.3.3
2.0.2
4.0.0
3.7.7
5.6.3
5.10.0
6.0.1
2.5.1
3.3.0
1.0.3
2.1.0
48.11.0
50.5.0
1.2.1
2.1.1
16.13.1
18.3.1
5.3.11
6.1.13
1.6.0
2.3.0
14.3.1
16.0.1
7.2.1
14.5.2
16.2.15
21.1.7
12.20.55
22.9.0
4.3.0
5.0.7
5.3.0
9.1.0
4.10.1
5.3.0
4.7.11
5.0.0
21.10.0
23.16.5
6.1.8
8.0.0
28.1.3
29.7.0
1.0.1
4.1.0
11.18.6
15.1.1
7.2.9
9.1.2
5.3.4
6.28.0
4.2.1
5.0.1
14.2.1
16.0.3
0.18.8
1.10.0
Bumps the major group with 3 updates in the /@shared/api directory: prettier, typescript and @lavamoat/allow-scripts. Bumps the major group with 1 update in the /@shared/helpers directory: typescript. Bumps the major group with 1 update in the /@stellar/freighter-api directory: @lavamoat/allow-scripts. Bumps the major group with 23 updates in the /extension directory:
2.8.8
3.3.3
2.0.2
4.0.0
2.5.1
3.3.0
1.6.0
2.3.0
14.3.1
16.0.1
7.2.1
14.5.2
4.7.11
5.0.0
16.2.15
21.1.7
12.20.55
22.9.0
4.3.0
5.0.7
5.14.9
6.0.0
5.3.0
9.1.0
4.10.1
5.3.0
21.10.0
23.16.5
6.1.8
8.0.0
28.1.3
29.7.0
1.0.1
4.1.0
11.18.6
15.1.1
7.2.9
9.1.2
5.3.4
6.28.0
4.2.1
5.0.1
14.2.1
16.0.3
0.18.8
1.10.0
Updates
@testing-library/dom
from 7.31.2 to 10.4.0Release notes
Sourced from
@testing-library/dom
's releases.... (truncated)
Commits
a86c54c
feat: Reduce caught exceptions in prettyDom (reland) (#1323)33555a3
Test highlighting ofprettyDOM
explicitly (#1324)20d9894
docs: add sieem as a contributor for code (#1330)306526b
fix: safer read of DEBUG_PRINT_LIMIT (#1329)fdc12ec
fix: Revert "feat: Reduce caught exceptions inprettyDom
(#1321)" (#1325)76cb73d
feat: Reduce caught exceptions inprettyDom
(#1321)0a8ad65
feat: Support anonymous custom elements when pretty printing DOM (#1319)77448ba
docs: update Greg Bergé's bio link (#1318)56543d5
feat: Add window events "pagehide" / "pageshow" (#1308)47fe879
chore: correct some typos and spelling errors (#1309)Updates
@testing-library/jest-dom
from 4.2.4 to 6.6.3Release notes
Sourced from
@testing-library/jest-dom
's releases.... (truncated)
Commits
5ba0156
fix: add vitest import when extending vitest matchers (#646)4468378
fix: remove recursive type reference in vitest types (#636)abba961
docs: add billyjanitsch as a contributor for bug (#644)9490615
docs: add G-Rath as a contributor for code (#643)ced792e
fix: fix lodash import in to-have-selection.js (#642)9b14804
feat: implement toHaveSelection (#637)f5b0e94
docs: add diegohaz as a contributor for ideas (#640)68e927e
docs: add pwolaq as a contributor for code, and test (#639)04005db
docs: add silviuaavram as a contributor for code, and test (#638)4723de3
docs: add mibcadet as a contributor for doc (#628)Updates
@types/testing-library__jest-dom
from 5.14.9 to 6.0.0Commits
Updates
@typescript-eslint/eslint-plugin
from 5.62.0 to 8.14.0Release notes
Sourced from
@typescript-eslint/eslint-plugin
's releases.... (truncated)
Changelog
Sourced from
@typescript-eslint/eslint-plugin
's changelog.... (truncated)
Commits
16fba0a
chore(release): publish 8.14.042d275c
fix(scope-manager): fix asserted increments not being marked as write referen...d27a9ac
fix(eslint-plugin): [no-misused-promises] improve report loc for methods (#10...c13b6b4
chore: fix lint and build website errors (#10288)5b2ebcd
feat(eslint-plugin): [await-thenable] report unnecessaryawait using
statem...22f7f25
fix(eslint-plugin): [no-unnecessary-condition] improve error message for lite...e2e9ffc
feat(eslint-plugin): [no-confusing-void-expression] add an option to ignore v...ac1f632
chore(release): publish 8.13.0f83a591
fix(eslint-plugin): [switch-exhaustiveness-check] add support for covering a ...3b97b55
chore: enable eslint-plugin-perfectionist on the rest of the repo (#10189)Updates
@typescript-eslint/parser
from 5.62.0 to 8.14.0Release notes
Sourced from
@typescript-eslint/parser
's releases.... (truncated)
Changelog
Sourced from
@typescript-eslint/parser
's changelog.... (truncated)
Commits
16fba0a
chore(release): publish 8.14.0ac1f632
chore(release): publish 8.13.04af866a
chore(release): publish 8.12.21edec1d
chore(release): publish 8.12.13413a2d
chore(release): publish 8.12.079c27a8
chore(release): publish 8.11.08d35958
chore: enable eslint-plugin-perfectionist on typescript-estree package (#9852)7effdea
chore(release): publish 8.10.0f9c49e3
feat: support TypeScript 5.6 (#9972)4666ed4
chore(release): publish 8.9.0Updates
eslint
from 8.57.0 to 9.15.0Release notes
Sourced from eslint's releases.
... (truncated)
Changelog
Sourced from eslint's changelog.
... (truncated)
Commits
6f37b07
9.15.01d99f29
Build: changelog update for 9.15.02967d91
chore: upgrade@eslint/js
@9
.15.0 (#19133)Report too large to display inline
View full report↗︎
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎
To accept the risk, merge this PR and you will not be notified again.
extension/package.json
extension/package.json
View full report↗︎
Next steps
What is a deprecated package?
The maintainer of the package marked it as deprecated. This could indicate that a single version should not be used, or that the package is no longer maintained and any new vulnerabilities will not be fixed.
Research the state of the package and determine if there are non-deprecated versions that can be used, or if it should be replaced with a new, supported solution.
Take a deeper look at the dependency
Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.
Remove the package
If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.
Mark a package as acceptable risk
To ignore an alert, reply with a comment starting with
@SocketSecurity ignore
followed by a space separated list ofecosystem/package-name@version
specifiers. e.g.@SocketSecurity ignore npm/foo@1.0.0
or ignore all packages with@SocketSecurity ignore-all
@SocketSecurity ignore npm/@types/history@5.0.0
@SocketSecurity ignore npm/@types/testing-library__jest-dom@6.0.0