Skip to content

chore(deps): update all dependencies#24

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

chore(deps): update all dependencies#24
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 1, 2025

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@1stg/app-config (source) ^7.2.1^14.0.0 age confidence devDependencies major
@1stg/lib-config (source) ^10.2.1^13.0.0 age confidence devDependencies major
@changesets/changelog-github (source) ^0.4.8^0.7.0 age confidence devDependencies minor
@size-limit/preset-small-lib ^8.1.2^12.0.0 age confidence devDependencies major
@types/node (source) ^18.7.16^24.0.0 age confidence devDependencies major
@types/react (source) ^18.0.28^19.0.0 age confidence devDependencies major
@types/react-dom (source) ^18.0.11^19.0.0 age confidence devDependencies major
@types/web ^0.0.93^0.0.349 age confidence devDependencies patch
@vitest/coverage-istanbul (source) ^0.23.2^4.0.0 age confidence devDependencies major
actions/checkout v3v6 age confidence action major
actions/setup-node v3v6 age confidence action major
amondnet/vercel-action v25v42 age confidence action major
andresz1/size-limit-action e7493a7 action pinDigest
codecov/codecov-action v3v6 age confidence action major
github/codeql-action v2v4 age confidence action major
pnpm (source) 7.11.011.1.1 age confidence packageManager major
pnpm/action-setup v2v6 age confidence action major
react (source) ^18.2.0^19.0.0 age confidence devDependencies major
react-dom (source) ^18.2.0^19.0.0 age confidence devDependencies major
react-router-dom (source) ^6.3.0^7.0.0 age confidence devDependencies major
sirv-cli ^2.0.2^3.0.0 age confidence devDependencies major
size-limit ^8.1.0^12.0.0 age confidence devDependencies major
typescript (source) ~4.7.4~6.0.0 age confidence pnpm.overrides major
typescript (source) ~4.7.4~6.0.0 age confidence resolutions major
typescript (source) ~4.7.4~6.0.0 age confidence devDependencies major
unplugin-auto-import ^0.11.2^21.0.0 age confidence devDependencies major
vitest (source) ^0.23.2^4.0.0 age confidence devDependencies major

Release Notes

1stG/configs (@​1stg/app-config)

v14.3.0

Compare Source

Minor Changes
Patch Changes

v14.2.0

Compare Source

Minor Changes
Patch Changes

v14.1.0

Compare Source

Minor Changes
Patch Changes

v14.0.0

Compare Source

Major Changes
Patch Changes

v13.1.0

Compare Source

Minor Changes
Patch Changes

v13.0.1

Compare Source

Patch Changes

v13.0.0

Compare Source

Major Changes
Patch Changes

v12.0.1

Compare Source

Patch Changes

v12.0.0

Compare Source

Major Changes
Patch Changes

v11.1.2

Compare Source

Patch Changes

v11.1.1

Compare Source

Patch Changes

v11.1.0

Compare Source

Minor Changes
Patch Changes

v11.0.3

Compare Source

Patch Changes

v11.0.2

Compare Source

Patch Changes

v11.0.1

Compare Source

Patch Changes

v11.0.0

Compare Source

Major Changes
  • d03df9f Thanks @​JounQin! - feat!: migrate to eslint-community packages, bump stylelint
Patch Changes

v10.0.1

Compare Source

Patch Changes

v10.0.0

Compare Source

Major Changes
Patch Changes

v9.0.1

Compare Source

Patch Changes

v9.0.0

Compare Source

Major Changes
Patch Changes

v8.1.0

Compare Source

Minor Changes
Patch Changes

v8.0.1

Compare Source

Patch Changes

v8.0.0

Compare Source

Major Changes
  • d03df9f Thanks @​JounQin! - feat!: migrate to eslint-community packages, bump stylelint
Minor Changes
Patch Changes
changesets/changesets (@​changesets/changelog-github)

v0.7.0

Compare Source

Minor Changes

v0.6.0

Compare Source

Minor Changes
Patch Changes

v0.5.2

Compare Source

v0.5.1

Compare Source

Patch Changes

v0.5.0

Compare Source

Minor Changes
  • #​1185 a971652 Thanks @​Andarist! - package.json#exports have been added to limit what (and how) code might be imported from the package.
Patch Changes
ai/size-limit (@​size-limit/preset-small-lib)

v12.1.0

Compare Source

  • Added disablePlugins option (by @​JPeer264).
  • Updated esbuild.

v12.0.1

Compare Source

v12.0.0

Compare Source

  • Moved jiti to optional dependency.
  • Removed chokidar dependency in favor of fs.watch.
  • Removed Node.js 18 support.
  • Updated open & esbuild dependencies.
  • Fixed docs (by @​nlopin & @​just-boris).

v11.2.0

Compare Source

v11.1.6

Compare Source

  • Updated chokidar.
  • Updated esbuild.
  • Updated jiti.

v11.1.5

Compare Source

  • Reduced dependencies (by @​ziebam).
  • Updated esbuild.

v11.1.4

Compare Source

v11.1.3

Compare Source

  • Updated esbuild.
  • Updated CSS loaders for webpack.

v11.1.2

Compare Source

v11.1.1

Compare Source

v11.1.0

Compare Source

v11.0.3

Compare Source

  • Fixed .mjs config support (by Arya Emami).
  • Updated esbuild.

v11.0.2

Compare Source

  • Fixed require is not defined regression.
  • Updated esbuild-visualizer.

v11.0.1

Compare Source

  • Updated estimo.
  • Updated lilconfig.

v11.0.0

Compare Source

v10.0.3

Compare Source

v10.0.2

Compare Source

  • Fixed require is not defined in webpack-css (by Andrey Medvedev).
  • Fixed webpack config defined as function support (by @​lev875).

v10.0.1

Compare Source

  • Fixed imports and exports between packages.

v10.0.0

Compare Source

v9.0.0

Compare Source

microsoft/TypeScript-DOM-Lib-Generator (@​types/web)

v0.0.349

Compare Source

asynciterable.d.ts

No changes

index.d.ts

No changes

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

No changes

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

No changes

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

No changes

ts5.9/iterable.d.ts

No changes

v0.0.348

Compare Source

asynciterable.d.ts

No changes

index.d.ts

New interfaces

  • DocumentPictureInPicture
  • DocumentPictureInPictureEvent
  • Origin
  • Serial
  • SerialPort

Modified

  • GPUSupportedLimits
    • Added: maxStorageBuffersInFragmentStage, maxStorageBuffersInVertexStage, maxStorageTexturesInFragmentStage, maxStorageTexturesInVertexStage
  • PerformanceResourceTiming
    • Added: contentType
  • Window
    • Added: documentPictureInPicture
Non-value types
  • AnimationEventInit
    • Added: animation
  • SanitizerConfig
    • Added: processingInstructions, removeProcessingInstructions
  • TransitionEventInit
    • Added: animation
  • CanvasTextDrawingStyles
    • Added: lang

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

New interfaces

  • DocumentPictureInPicture
  • DocumentPictureInPictureEvent
  • Origin
  • Serial
  • SerialPort

Modified

  • GPUSupportedLimits
    • Added: maxStorageBuffersInFragmentStage, maxStorageBuffersInVertexStage, maxStorageTexturesInFragmentStage, maxStorageTexturesInVertexStage
  • Navigator
    • Added: serial
  • PerformanceResourceTiming
    • Added: contentType
  • Window
    • Added: documentPictureInPicture
Non-value types
  • AnimationEventInit
    • Added: animation
  • SanitizerConfig
    • Added: processingInstructions, removeProcessingInstructions
  • TransitionEventInit
    • Added: animation
  • CanvasTextDrawingStyles
    • Added: lang

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

New interfaces

  • DocumentPictureInPicture
  • DocumentPictureInPictureEvent
  • Origin
  • Serial
  • SerialPort

Modified

  • GPUSupportedLimits
    • Added: maxStorageBuffersInFragmentStage, maxStorageBuffersInVertexStage, maxStorageTexturesInFragmentStage, maxStorageTexturesInVertexStage
  • Navigator
    • Added: serial
  • PerformanceResourceTiming
    • Added: contentType
  • Window
    • Added: documentPictureInPicture
Non-value types
  • AnimationEventInit
    • Added: animation
  • SanitizerConfig
    • Added: processingInstructions, removeProcessingInstructions
  • TransitionEventInit
    • Added: animation
  • CanvasTextDrawingStyles
    • Added: lang

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

New interfaces

  • DocumentPictureInPicture
  • DocumentPictureInPictureEvent
  • Origin
  • Serial
  • SerialPort

Modified

  • GPUSupportedLimits
    • Added: maxStorageBuffersInFragmentStage, maxStorageBuffersInVertexStage, maxStorageTexturesInFragmentStage, maxStorageTexturesInVertexStage
  • Navigator
    • Added: serial
  • PerformanceResourceTiming
    • Added: contentType
  • Window
    • Added: documentPictureInPicture
Non-value types
  • AnimationEventInit
    • Added: animation
  • SanitizerConfig
    • Added: processingInstructions, removeProcessingInstructions
  • TransitionEventInit
    • Added: animation
  • CanvasTextDrawingStyles
    • Added: lang

ts5.9/iterable.d.ts

No changes

v0.0.347

Compare Source

asynciterable.d.ts

No changes

index.d.ts

No changes

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

No changes

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

No changes

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

No changes

ts5.9/iterable.d.ts

No changes

v0.0.346

Compare Source

asynciterable.d.ts

No changes

index.d.ts

No changes

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

No changes

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

No changes

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

No changes

ts5.9/iterable.d.ts

No changes

v0.0.345

Compare Source

asynciterable.d.ts

No changes

index.d.ts

New interfaces

  • CSSFontFaceDescriptors

Modified

  • RTCIceTransport
    • Added: role
  • VisualViewport
    • Added: onscrollend
Non-value types
  • VisualViewportEventMap
    • Added: "scrollend"

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

New interfaces

  • CSSFontFaceDescriptors

Modified

  • HighlightRegistry
    • Added: highlightsFromPoint
  • RTCIceTransport
    • Added: role
  • VisualViewport
    • Added: onscrollend
Non-value types
  • VisualViewportEventMap
    • Added: "scrollend"

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

New interfaces

  • CSSFontFaceDescriptors

Modified

  • HighlightRegistry
    • Added: highlightsFromPoint
  • RTCIceTransport
    • Added: role
  • VisualViewport
    • Added: onscrollend
Non-value types
  • VisualViewportEventMap
    • Added: "scrollend"

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

New interfaces

  • CSSFontFaceDescriptors

Modified

  • HighlightRegistry
    • Added: highlightsFromPoint
  • RTCIceTransport
    • Added: role
  • VisualViewport
    • Added: onscrollend
Non-value types
  • VisualViewportEventMap
    • Added: "scrollend"

ts5.9/iterable.d.ts

No changes

v0.0.344

Compare Source

asynciterable.d.ts

No changes

index.d.ts

No changes

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

No changes

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

No changes

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

No changes

ts5.9/iterable.d.ts

No changes

v0.0.343

Compare Source

asynciterable.d.ts

No changes

index.d.ts

No changes

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

No changes

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

No changes

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

No changes

ts5.9/iterable.d.ts

No changes

v0.0.342

Compare Source

asynciterable.d.ts

No changes

index.d.ts

No changes

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

No changes

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

No changes

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

No changes

ts5.9/iterable.d.ts

No changes

v0.0.341

Compare Source

asynciterable.d.ts

No changes

index.d.ts

No changes

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

No changes

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

No changes

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

No changes

ts5.9/iterable.d.ts

No changes

v0.0.340

Compare Source

asynciterable.d.ts

No changes

index.d.ts

Non-value types
  • HTMLHyperlinkElementUtils
    • Removed: hash, host, hostname, origin, password, pathname, port, protocol, search, username

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

Non-value types
  • HTMLHyperlinkElementUtils
    • Removed: hash, host, hostname, origin, password, pathname, port, protocol, search, username

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

Non-value types
  • HTMLHyperlinkElementUtils
    • Removed: hash, host, hostname, origin, password, pathname, port, protocol, search, username

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

Non-value types
  • HTMLHyperlinkElementUtils
    • Removed: hash, host, hostname, origin, password, pathname, port, protocol, search, username

ts5.9/iterable.d.ts

No changes

v0.0.339

Compare Source

asynciterable.d.ts

No changes

index.d.ts

New interfaces

  • CloseWatcher
  • WebTransportReceiveStream
  • WebTransportSendStream

Modified

  • HTMLInputElement
    • Added: colorSpace
  • HTMLMediaElement
    • Added: captureStream
  • PerformanceResourceTiming
    • Added: deliveryType, finalResponseHeadersStart, firstInterimResponseStart
  • WebTransport
    • Added: congestionControl, protocol, reliability, getStats

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

New interfaces

  • CloseWatcher
  • WebTransportReceiveStream
  • WebTransportSendStream

Modified

  • HTMLInputElement
    • Added: colorSpace
  • HTMLMediaElement
    • Added: captureStream
  • PerformanceResourceTiming
    • Added: deliveryType, finalResponseHeadersStart, firstInterimResponseStart
  • WebTransport
    • Added: congestionControl, protocol, reliability, getStats

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

New interfaces

  • CloseWatcher
  • WebTransportReceiveStream
  • WebTransportSendStream

Modified

  • HTMLInputElement
    • Added: colorSpace
  • HTMLMediaElement
    • Added: captureStream
  • PerformanceResourceTiming
    • Added: deliveryType, finalResponseHeadersStart, firstInterimResponseStart
  • WebTransport
    • Added: congestionControl, protocol, reliability, getStats

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

New interfaces

  • CloseWatcher
  • WebTransportReceiveStream
  • WebTransportSendStream

Modified

  • HTMLInputElement
    • Added: colorSpace
  • HTMLMediaElement
    • Added: captureStream
  • PerformanceResourceTiming
    • Added: deliveryType, finalResponseHeadersStart, firstInterimResponseStart
  • WebTransport
    • Added: congestionControl, protocol, reliability, getStats

ts5.9/iterable.d.ts

No changes

v0.0.338

Compare Source

asynciterable.d.ts

No changes

index.d.ts

No changes

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

No changes

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

No changes

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

No changes

ts5.9/iterable.d.ts

No changes

v0.0.337

Compare Source

asynciterable.d.ts

No changes

index.d.ts

No changes

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

No changes

ts5.5/iterable.d.ts

No changes

ts5.6/asynciterable.d.ts

No changes

ts5.6/index.d.ts

No changes

ts5.6/iterable.d.ts

No changes

ts5.9/asynciterable.d.ts

No changes

ts5.9/index.d.ts

No changes

ts5.9/iterable.d.ts

No changes

v0.0.336

Compare Source

asynciterable.d.ts

No changes

index.d.ts

New interfaces

  • GPU
  • GPUAdapter

Modified

  • CustomElementRegistry
    • Added: initialize
  • Element
    • Added: customElementRegistry
  • GPUDevice
    • Added: createBindGroupLayout
  • HTMLTemplateElement
    • Added: shadowRootCustomElementRegistry
  • NavigationPrecommitController
    • Added: addHandler
Non-value types
  • DocumentOrShadowRoot
    • Added: customElementRegistry

iterable.d.ts

No changes

ts5.5/asynciterable.d.ts

No changes

ts5.5/index.d.ts

New interfaces

  • GPU
  • GPUAdapter

Modified

  • CustomElementRegistry
    • Added: initialize
  • Element
    • Added: customElementRegistry
  • GPUDevice
    • Added: createBindGroupLayout
  • HTMLTemplateElement
    • Added: `shad

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented Apr 1, 2025

⚠️ No Changeset found

Latest commit: fbc2b23

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented Apr 1, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Comment @coderabbitai help to get the list of available commands and usage tips.

@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 6, 2025

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @surma/rollup-plugin-off-main-thread is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@surma/rollup-plugin-off-main-thread@2.2.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@surma/rollup-plugin-off-main-thread@2.2.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @typescript-eslint/eslint-plugin is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@1stg/lib-config@13.0.1npm/@1stg/app-config@14.3.0npm/@typescript-eslint/eslint-plugin@8.59.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@typescript-eslint/eslint-plugin@8.59.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm chrono-node is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/chrono-node@2.9.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/chrono-node@2.9.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm commander is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/commander@10.0.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/commander@10.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm diff-sequences is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@1stg/lib-config@13.0.1npm/@1stg/app-config@14.3.0npm/diff-sequences@27.5.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/diff-sequences@27.5.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: pnpm-lock.yamlnpm/@pkgr/webpack-mdx@2.2.0npm/entities@4.5.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@4.5.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: pnpm-lock.yamlnpm/entities@6.0.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@6.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm es-abstract is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/es-abstract@1.24.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-abstract@1.24.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate Bot force-pushed the renovate/all branch from 05628a4 to 7267033 Compare May 6, 2025 05:59
@renovate renovate Bot force-pushed the renovate/all branch from 7267033 to 8819f02 Compare May 9, 2025 06:56
@renovate renovate Bot force-pushed the renovate/all branch from 8819f02 to ff43122 Compare May 13, 2025 17:15
@renovate renovate Bot force-pushed the renovate/all branch 2 times, most recently from c96723f to 44ade22 Compare May 17, 2025 07:24
@renovate renovate Bot force-pushed the renovate/all branch from 44ade22 to 4aa678b Compare May 18, 2025 15:04
@renovate renovate Bot force-pushed the renovate/all branch from 4aa678b to 5cfc433 Compare May 29, 2025 07:03
@renovate renovate Bot force-pushed the renovate/all branch from 5cfc433 to fcb9e4a Compare June 1, 2025 07:43
@renovate renovate Bot force-pushed the renovate/all branch from fcb9e4a to a8ff2b2 Compare June 4, 2025 23:57
@renovate renovate Bot force-pushed the renovate/all branch from a8ff2b2 to e7679e0 Compare June 5, 2025 05:14
@renovate renovate Bot force-pushed the renovate/all branch from e7679e0 to f009a6c Compare June 8, 2025 18:43
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Mar 19, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​types/​node@​25.7.0 ⏵ 24.12.3100 +110081 +196100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants