Skip to content

Conversation

github-actions[bot]
Copy link
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@keystar/[email protected]

Patch Changes

@keystatic/[email protected]

Patch Changes

@keystatic/[email protected]

Patch Changes

@keystatic/[email protected]

Patch Changes

@keystatic/[email protected]

Patch Changes

@keystar/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@keystatic/[email protected]

Patch Changes

[email protected]

Patch Changes

Copy link

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedserver-only@​0.0.11001004375100
Addedescape-string-regexp@​4.0.01001006976100
Addedfast-deep-equal@​3.1.31001009976100
Addedjs-yaml@​4.1.010010010077100
Addedsignal-exit@​3.0.71001007979100
Addedjson5@​2.2.310010010079100
Addedprop-types@​15.8.19910010080100
Addedlodash@​4.17.211001008680100
Addedreact@​19.0.01001008397100
Addedsvgo@​3.3.29910010085100
Addedreact-dom@​19.0.01001009297100

View full report

Copy link

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
[email protected] has a License Policy Violation.

License: CC-BY-SA-4.0 (package/LICENSE)

From: pnpm-lock.yamlnpm/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
[email protected] has a License Policy Violation.

License: GPL-2.0 (package/LICENSE)

From: pnpm-lock.yamlnpm/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants