Skip to content

chore: update and fix dependencies for package publishing - #780

Merged
fraxken merged 1 commit into
masterfrom
update-dependencies
Jul 11, 2026
Merged

chore: update and fix dependencies for package publishing#780
fraxken merged 1 commit into
masterfrom
update-dependencies

Conversation

@fraxken

Copy link
Copy Markdown
Member

No description provided.

@changeset-bot

changeset-botBot commented Jul 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d4bae56

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 5 packages
NameType
@nodesecure/documentation-uiPatch
@nodesecure/vis-networkPatch
@nodesecure/serverPatch
@nodesecure/cachePatch
@nodesecure/cliPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@socket-security

socket-securityBot commented Jul 9, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: npm @emnapi/runtime is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:?npm/vite@8.1.4npm/@emnapi/runtime@1.11.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/runtime@1.11.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: npm @sigstore/tuf is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:?npm/@nodesecure/scanner@10.13.0npm/@sigstore/tuf@5.0.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@sigstore/tuf@5.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: npm css-tree is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:?npm/stylelint@17.14.0npm/css-tree@3.2.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/css-tree@3.2.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: npm eslint-plugin-jsdoc is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:package.jsonnpm/eslint-plugin-jsdoc@63.0.12

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/eslint-plugin-jsdoc@63.0.12. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@fraxken
fraxkenforce-pushed the update-dependencies branch 2 times, most recently from 4fffeb9 to fd42ee2CompareJuly 10, 2026 19:56
@fraxken
fraxken marked this pull request as ready for review July 10, 2026 19:57
@fraxken
fraxkenforce-pushed the update-dependencies branch from fd42ee2 to 3f7d021CompareJuly 11, 2026 11:40
@fraxken
fraxkenforce-pushed the update-dependencies branch from 3f7d021 to d4bae56CompareJuly 11, 2026 12:37
@fraxken
fraxken merged commit 0d662da into masterJul 11, 2026
11 checks passed
@fraxken
fraxken deleted the update-dependencies branch July 11, 2026 16:37
@github-actionsgithub-actionsBot mentioned this pull request Jul 11, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@fraxken@clemgbld