Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Sep 1, 2024

Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more here.

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, on day 1 of the month ( * 0-3 1 * * ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link

socket-security bot commented Sep 1, 2024

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednode-releases@​2.0.18 ⏵ 2.0.191001004177100
Updatedis-core-module@​2.15.1 ⏵ 2.16.167 +110080 +152100
Updated@​pkgr/​core@​0.1.1 ⏵ 0.2.9100 +110062 +188100
Updated@​babel/​helper-validator-option@​7.24.8 ⏵ 7.27.11001006989100
Updatedeslint-config-prettier@​9.1.0 ⏵ 9.1.21001007090100
Updated@​babel/​helper-validator-identifier@​7.24.7 ⏵ 7.27.11001007189100
Updated@​babel/​code-frame@​7.24.7 ⏵ 7.27.110010072 +189100
Updated@​babel/​helper-string-parser@​7.24.8 ⏵ 7.27.11001007289100
Updated@​changesets/​get-release-plan@​4.0.11 ⏵ 4.0.131001007387 -5100
Updated@​babel/​helper-compilation-targets@​7.25.2 ⏵ 7.27.210010073 +189100
Updated@​babel/​helper-module-imports@​7.24.7 ⏵ 7.27.11001007389100
Updatedupdate-browserslist-db@​1.1.0 ⏵ 1.1.31001007479100
Updated@​babel/​template@​7.25.0 ⏵ 7.27.2100 +110074 +190100
Added@​babel/​helper-globals@​7.28.01001007486100
Updated@​openzeppelin/​docs-utils@​0.1.5 ⏵ 0.1.675 +21008783100
Updatedistanbul-reports@​3.1.7 ⏵ 3.2.0100 +11007587100
Updated@​babel/​helper-module-transforms@​7.25.2 ⏵ 7.28.3100 +110075 +193100
Updated@​frangio/​servbot@​0.2.5 ⏵ 0.3.0-176 +1100100 +177100
Updatedescalade@​3.1.2 ⏵ 3.2.0100 +1100100 +176100
Updated@​babel/​compat-data@​7.25.4 ⏵ 7.28.0100 +110076 +192100
Updated@​humanwhocodes/​config-array@​0.11.14 ⏵ 0.13.0100 +1100100 +176100
Updatedprocess-on-spawn@​1.0.0 ⏵ 1.1.01001008677100
Updatedimport-fresh@​3.3.0 ⏵ 3.3.1100 +110081 +377100
Updatedreusify@​1.0.4 ⏵ 1.1.010010010077100
Updatedjsesc@​2.5.2 ⏵ 3.1.010010010077100
Updatedend-of-stream@​1.4.4 ⏵ 1.4.5100 +110083 +177100
Updatedchardet@​0.7.0 ⏵ 2.1.0100100100 +678100
Updated@​babel/​generator@​7.25.5 ⏵ 7.28.310010078 +194100
Updated@​babel/​runtime@​7.27.1 ⏵ 7.28.31001007894100
Updated@​babel/​traverse@​7.25.4 ⏵ 7.28.3100 +110078 +195100
Updated@​babel/​helpers@​7.25.0 ⏵ 7.28.399100 +57894100
Updated@​babel/​core@​7.25.2 ⏵ 7.28.39810078 +194100
See 29 more rows in the dashboard

View full report

@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from 3d33a5b to 76bcc7e Compare September 10, 2024 17:59
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 76bcc7e to a07dc72 Compare September 20, 2024 20:50
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from a07dc72 to 07c1934 Compare January 13, 2025 21:23
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 07c1934 to 1d25c19 Compare January 21, 2025 22:20
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 1d25c19 to 427d4e6 Compare March 19, 2025 20:39
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 427d4e6 to ccd0637 Compare April 14, 2025 14:42
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from ccd0637 to 51f385c Compare May 12, 2025 21:13
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 51f385c to 594665d Compare June 15, 2025 11:54
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from f49e021 to b009029 Compare August 13, 2025 17:13
Copy link

socket-security bot commented Aug 13, 2025

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Low
prettier@3.6.2 is a AI-detected potential code anomaly.

Notes: No definitive malware detected in this fragment. The main security concern is supply-chain risk from dynamically loading plugins from potentially untrusted sources. To mitigate, enforce strict plugin provenance, disable remote plugin loading, verify plugin integrity, and apply least-privilege execution for plugins.

Confidence: 1.00

Severity: 0.60

From: package.jsonnpm/prettier@3.6.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/prettier@3.6.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
process-on-spawn@1.1.0 is a AI-detected potential code anomaly.

Notes: The module is a global hook that intercepts and allows modification of all child process spawns. The code itself is not overtly malicious (no embedded exfiltration or network code), but it creates a high-risk capability: listeners receive full environment and spawn metadata and can both read secrets and modify what is executed. If untrusted or malicious listeners can be registered, this becomes a significant supply-chain/backdoor risk. Recommend careful review of any code that registers listeners and restrict usage to trusted code only; consider whether such global monkey-patching is acceptable for your threat model.

Confidence: 1.00

Severity: 0.60

From: yarn.locknpm/process-on-spawn@1.1.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/process-on-spawn@1.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from b009029 to 9f2c68a Compare August 19, 2025 17:14
@renovate renovate bot force-pushed the renovate/lock-file-maintenance branch from 9f2c68a to d5a7caf Compare August 31, 2025 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants