storybookjs / react-native

đź““ Storybook for React Native!
https://storybook.js.org
MIT License
995 stars 142 forks source link

feat: update lerna #554

Closed dannyhw closed 4 months ago

dannyhw commented 4 months ago

Issue:

What I did

How to test

Please explain how to test your changes and consider the following questions

If your answer is yes to any of these, please make sure to include it in your PR.

socket-security[bot] commented 4 months ago

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@lerna/create@8.1.2 Transitive: environment, eval, filesystem, network, shell, unsafe +518 580 MB jameshenry, nrwlowner
npm/@npmcli/agent@2.2.1 Transitive: environment, network +9 478 kB fritzy, gar, lukekarrys, ...2 more
npm/@npmcli/git@5.0.4 filesystem Transitive: environment, shell +13 202 kB npm-cli-ops
npm/@npmcli/package-json@5.0.0 filesystem Transitive: environment, shell +45 1.6 MB npm-cli-ops
npm/@npmcli/promise-spawn@7.0.1 environment, shell Transitive: filesystem +2 62.5 kB npm-cli-ops
npm/@npmcli/run-script@7.0.2 environment, filesystem Transitive: network, shell +79 6.07 MB npm-cli-ops
npm/@nrwl/devkit@18.0.4 Transitive: environment, eval, filesystem, network, shell, unsafe +148 508 MB altan-nrwl, jack-nrwl, juristr, ...3 more
npm/@nrwl/tao@18.0.4 Transitive: environment, eval, filesystem, network, shell, unsafe +140 507 MB altan-nrwl, jack-nrwl, juristr, ...3 more
npm/@nx/devkit@18.0.4 Transitive: environment, eval, filesystem, network, shell, unsafe +148 508 MB jack-nrwl, martin.malinowski, nexumag, ...2 more
npm/@nx/nx-darwin-arm64@18.0.4 None 0 7.01 MB nrwl-jason
npm/@nx/nx-darwin-x64@18.0.4 None 0 7.46 MB jack-nrwl, martin.malinowski, nexumag, ...2 more
npm/@nx/nx-freebsd-x64@18.0.4 None 0 9.29 MB jack-nrwl, martin.malinowski, nexumag, ...2 more
npm/@nx/nx-linux-arm-gnueabihf@18.0.4 None 0 9.13 MB jack-nrwl, martin.malinowski, nexumag, ...2 more
npm/@nx/nx-linux-arm64-gnu@18.0.4 None 0 9.98 MB nrwl-jason
npm/@nx/nx-linux-arm64-musl@18.0.4 None 0 9.93 MB nrwl-jason
npm/@nx/nx-linux-x64-gnu@18.0.4 None 0 9.77 MB jack-nrwl, martin.malinowski, nexumag, ...2 more
npm/@nx/nx-linux-x64-musl@18.0.4 None 0 9.76 MB jack-nrwl, martin.malinowski, nexumag, ...2 more
npm/@nx/nx-win32-arm64-msvc@18.0.4 None 0 5.85 MB jack-nrwl, martin.malinowski, nexumag, ...2 more
npm/@nx/nx-win32-x64-msvc@18.0.4 None 0 6.62 MB jack-nrwl, martin.malinowski, nexumag, ...2 more
npm/@octokit/plugin-paginate-rest@6.1.2 Transitive: network +21 5.52 MB octokitbot
npm/@octokit/plugin-rest-endpoint-methods@7.2.3 Transitive: network +21 7.05 MB octokitbot
npm/@octokit/rest@19.0.11 Transitive: network +25 7.27 MB octokitbot
npm/@octokit/tsconfig@1.0.2 None 0 2.63 kB octokitbot
npm/@sigstore/bundle@2.1.1 None +1 253 kB bdehamer
npm/@sigstore/core@1.0.0 None 0 88.5 kB bdehamer
npm/@sigstore/sign@2.2.2 environment Transitive: filesystem, network, shell +66 3.39 MB bdehamer
npm/@sigstore/tuf@2.3.0 environment, filesystem Transitive: network, shell +67 3.35 MB bdehamer
npm/@sigstore/verify@1.0.0 None +3 414 kB bdehamer
npm/byte-size@8.1.1 None 0 32.8 kB 75lb
npm/cacache@18.0.2 filesystem Transitive: environment, shell +42 2.11 MB npm-cli-ops
npm/cmd-shim@6.0.1 filesystem 0 11.8 kB nlf
npm/conventional-changelog-angular@7.0.0 filesystem +4 33.1 kB oss-bot
npm/conventional-changelog-core@5.0.1 shell Transitive: environment, eval, filesystem +119 7.45 MB oss-bot
npm/conventional-changelog-preset-loader@3.0.0 None 0 5.97 kB oss-bot
npm/conventional-changelog-writer@6.0.1 filesystem Transitive: environment, eval +68 6.22 MB oss-bot
npm/conventional-commits-filter@3.0.0 None +2 60.6 kB oss-bot
npm/conventional-commits-parser@4.0.0 Transitive: environment, filesystem +62 1.03 MB oss-bot
npm/conventional-recommended-bump@7.0.1 Transitive: environment, filesystem, shell +74 1.2 MB oss-bot
npm/cosmiconfig@8.3.6 filesystem Transitive: environment, unsafe +21 32.9 MB d-fischer
npm/dotenv@16.3.2 environment, filesystem 0 72.1 kB motdotla
npm/envinfo@7.8.1 environment, eval, filesystem, shell 0 160 kB tabrindle
npm/git-raw-commits@3.0.0 shell Transitive: environment, filesystem +61 1.02 MB oss-bot
npm/git-semver-tags@5.0.1 shell Transitive: environment, filesystem +55 821 kB oss-bot
npm/graceful-fs@4.2.11 environment, filesystem 0 32.5 kB isaacs
npm/init-package-json@5.0.0 filesystem Transitive: environment, shell, unsafe +41 1.5 MB lukekarrys
npm/is-ci@3.0.1 Transitive: environment +1 29.9 kB sibiraj-s
npm/isexe@3.1.1 environment, filesystem 0 43 kB isaacs
npm/lerna@8.1.2 Transitive: environment, eval, filesystem, network, shell, unsafe +538 586 MB evocateur, hzoo, jameshenry, ...1 more
npm/libnpmaccess@7.0.2 Transitive: environment, filesystem, network, shell +70 2.77 MB lukekarrys
npm/libnpmpublish@7.3.0 environment, filesystem Transitive: network, shell +89 3.64 MB lukekarrys
npm/make-fetch-happen@13.0.0 network Transitive: environment, filesystem, shell +62 2.96 MB npm-cli-ops
npm/minipass-collect@2.0.1 None 0 4.96 kB isaacs
npm/node-gyp@10.0.1 environment, shell Transitive: filesystem, network +73 6.01 MB lukekarrys
npm/node-machine-id@1.1.12 environment, eval, shell 0 35.8 kB automation-stack
npm/npm-pick-manifest@9.0.0 None +5 54.2 kB npm-cli-ops
npm/nx@18.0.4 Transitive: environment, eval, filesystem, network, shell, unsafe +140 507 MB altan-nrwl, jack-nrwl, juristr, ...4 more
npm/pacote@17.0.6 environment, filesystem, network Transitive: shell +116 7.3 MB npm-cli-ops
npm/promzard@1.0.0 filesystem, unsafe +2 22.1 kB lukekarrys
npm/read@2.1.0 None +1 11.3 kB npm-cli-ops
npm/string_decoder@1.3.0 None +1 46.5 kB matteo.collina
npm/tuf-js@2.2.0 filesystem Transitive: environment, network, shell +65 3.09 MB eugenethehub

đźš® Removed packages: npm/@isaacs/string-locale-compare@1.1.0, npm/@lerna/child-process@6.6.2, npm/@lerna/create@6.6.2, npm/@lerna/legacy-package-management@6.6.2, npm/@npmcli/agent@2.2.0, npm/@npmcli/arborist@6.2.3, npm/@npmcli/git@4.1.0, npm/@npmcli/map-workspaces@3.0.4, npm/@npmcli/metavuln-calculator@5.0.1, npm/@npmcli/move-file@2.0.1, npm/@npmcli/name-from-folder@2.0.0, npm/@npmcli/package-json@3.1.1, npm/@npmcli/promise-spawn@6.0.2, npm/@npmcli/query@3.0.1, npm/@npmcli/run-script@4.1.7, npm/@nrwl/cli@15.9.7, npm/@nrwl/devkit@15.9.7, npm/@nrwl/tao@15.9.7, npm/@octokit/openapi-types@12.11.0, npm/@octokit/plugin-paginate-rest@3.1.0, npm/@octokit/plugin-rest-endpoint-methods@6.8.1, npm/@octokit/rest@19.0.3, npm/@parcel/watcher@2.0.4, npm/abbrev@1.1.1, npm/are-we-there-yet@4.0.2, npm/bin-links@4.0.3, npm/byte-size@7.0.0, npm/cmd-shim@5.0.0, npm/common-ancestor-path@1.0.1, npm/config-chain@1.1.12, npm/conventional-changelog-angular@5.0.12, npm/conventional-changelog-core@4.2.4, npm/conventional-changelog-preset-loader@2.3.4, npm/conventional-changelog-writer@5.0.1, npm/conventional-commits-filter@2.0.7, npm/conventional-commits-parser@3.2.4, npm/conventional-recommended-bump@6.1.0, npm/cosmiconfig@7.0.0, npm/dot-prop@6.0.1, npm/dotenv@10.0.0, npm/file-url@3.0.0, npm/gauge@5.0.1, npm/git-raw-commits@2.0.11, npm/git-semver-tags@4.1.1, npm/graceful-fs@4.2.10, npm/init-package-json@3.0.2, npm/is-ci@2.0.0, npm/json-stringify-nice@1.1.4, npm/just-diff-apply@5.5.0, npm/just-diff@6.0.2, npm/lerna@6.6.2, npm/libnpmaccess@6.0.4, npm/libnpmpublish@7.1.4, npm/mkdirp-infer-owner@2.0.0, npm/node-addon-api@3.2.1, npm/node-gyp-build@4.8.0, npm/node-gyp@9.4.1, npm/npm-pick-manifest@8.0.2, npm/nx@15.9.7, npm/pacote@15.1.1, npm/parse-conflict-json@3.0.1, npm/pretty-format@29.4.3, npm/promise-all-reject-late@1.0.1, npm/promise-call-limit@1.0.2, npm/promzard@0.3.0, npm/proto-list@1.2.4, npm/q@1.5.1, npm/read-cmd-shim@3.0.0, npm/read-package-json@5.0.1, npm/read@1.0.7, npm/tempy@1.0.0, npm/through2@4.0.2, npm/treeverse@3.0.0, npm/unique-slug@3.0.0, npm/v8-compile-cache@2.3.0, npm/validate-npm-package-name@4.0.0, npm/walk-up-path@1.0.0, npm/write-file-atomic@4.0.1, npm/yargs-parser@20.2.4

View full report↗︎

socket-security[bot] commented 4 months ago

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring: npm/@lerna/create@8.1.2, npm/@npmcli/agent@2.2.1, npm/@npmcli/git@5.0.4, npm/@npmcli/package-json@5.0.0, npm/@npmcli/promise-spawn@7.0.1, npm/@npmcli/run-script@7.0.2, npm/@nrwl/devkit@18.0.4, npm/@nrwl/tao@18.0.4, npm/@nx/devkit@18.0.4, npm/@nx/nx-darwin-arm64@18.0.4, npm/@nx/nx-darwin-x64@18.0.4, npm/@nx/nx-freebsd-x64@18.0.4, npm/@nx/nx-linux-arm-gnueabihf@18.0.4, npm/@nx/nx-linux-arm64-gnu@18.0.4, npm/@nx/nx-linux-arm64-musl@18.0.4, npm/@nx/nx-linux-x64-gnu@18.0.4, npm/@nx/nx-linux-x64-musl@18.0.4, npm/@nx/nx-win32-arm64-msvc@18.0.4, npm/@nx/nx-win32-x64-msvc@18.0.4, npm/@octokit/plugin-paginate-rest@6.1.2, npm/@octokit/plugin-rest-endpoint-methods@7.2.3, npm/@octokit/rest@19.0.11, npm/@octokit/tsconfig@1.0.2, npm/@octokit/types@10.0.0, npm/@sigstore/bundle@2.1.1, npm/@sigstore/core@1.0.0, npm/@sigstore/sign@2.2.2, npm/@sigstore/tuf@2.3.0, npm/@sigstore/verify@1.0.0, npm/@tufjs/canonical-json@2.0.0, npm/@tufjs/models@2.0.0, npm/byte-size@8.1.1, npm/cacache@18.0.2, npm/cliui@8.0.1, npm/cmd-shim@6.0.1, npm/conventional-changelog-angular@7.0.0, npm/conventional-changelog-core@5.0.1, npm/conventional-changelog-preset-loader@3.0.0, npm/conventional-changelog-writer@6.0.1, npm/conventional-commits-filter@3.0.0, npm/conventional-commits-parser@4.0.0, npm/conventional-recommended-bump@7.0.1, npm/cosmiconfig@8.3.6, npm/dotenv@16.3.2, npm/envinfo@7.8.1, npm/git-raw-commits@3.0.0, npm/git-semver-tags@5.0.1, npm/graceful-fs@4.2.11, npm/hosted-git-info@7.0.1, npm/init-package-json@5.0.0, npm/is-ci@3.0.1, npm/isexe@3.1.1, npm/lerna@8.1.2, npm/libnpmaccess@7.0.2, npm/libnpmpublish@7.3.0, npm/make-fetch-happen@13.0.0, npm/minipass-collect@2.0.1, npm/mute-stream@1.0.0, npm/node-gyp@10.0.1, npm/node-machine-id@1.1.12, npm/normalize-package-data@6.0.0, npm/npm-package-arg@11.0.1, npm/npm-packlist@8.0.2, npm/npm-pick-manifest@9.0.0, npm/npm-registry-fetch@16.1.0, npm/nx@18.0.4, npm/ora@5.3.0, npm/pacote@17.0.6, npm/promzard@1.0.0, npm/read-package-json@7.0.0, npm/read@2.1.0, npm/sigstore@2.2.1, npm/string_decoder@1.3.0, npm/tuf-js@2.2.0, npm/which@4.0.0, npm/yargs-parser@20.2.9

View full report↗︎

Next steps

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

dannyhw commented 4 months ago

@SocketSecurity ignore-all