-
Notifications
You must be signed in to change notification settings - Fork 1
Update package.json #29
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
📊 Package size report 8%↑
Unchanged files
🤖 This report was automatically generated by pkg-size-action |
|
critical 🚨 4 | medium |
low 🔷 1 |
🔍 The following behaviors have been detected in the dependency tree during installation
🚨 Critical severity
📑🔀
2 categories
📑🔀 | 2 categories |
-
🔀 Typosquatting ∙ 3 packages
⚠️ Medium severity
📡🔎
2 categories
📡🔎 | 2 categories |
🔷 Low severity
📑
1 category
📑 | 1 category |
-
📑 Metadata ∙ 1 package
-
📦 source-map-support@0.5.21 ∙ 1 occurrence ∙ 1 kind of issue ∙ open 🔗
-
This package version is 0.X.Y: the semver spec mandates those versions for initial development meaning that anything may change at any time and the public API of this package should not be considered stable.
∙ 1 total occurrence
Name Version Transitive Dependency Occurrences More source-map-support 0.5.21 1 🔗
-
-
### 🚩 Some problems have been encountered
🔗 Package not analysed yet ∙ 30 occurrences ∙ Package not analysed yet
- @types/react@17.0.69
- linkis-website@6.0.4
- commons-skin@6.0.4
- yinhai@6.0.4
- tslint-slick@5.0.2
- sshwifty-ui@6.0.2
- generate-protocol@6.0.2
- 33-js-concepts@6.0.2
- unieap-ios@6.0.4
- unieap-android@6.0.4
- tap-mocha-reporter@5.0.4
- aliyundrive@6.0.4
- xterm-addon-unicode-graphemes@6.0.5
- sequelize-orm@6.0.2
- unieap@6.0.4
- hexojs@6.0.2
- echarts-www@6.0.4
- arduino-ide-extension@2.2.3
- unieap-spring@6.0.4
- unieap-cloud@6.0.4
- sshwifty@6.0.2
- spring-projects@6.0.4
- babel-preset-slick@7.0.5
- tsconfig-slick@3.0.3
- scan4all@6.0.4
- layui.js@6.0.2
- 30-days-of-javascript@6.0.2
- xterm-addon-clipboard@6.0.4
- www-site@6.0.4
- rocketmq-site@6.0.4
Powered by listen.dev
🚀 Pull Request Security Summary
Issues Impacting Your Code🚨 Critical Issues Affecting Used Code (2)
|
🔐 Security Compliance Report
Comprehensive Risk Assessment🚨 Critical Risk Profile (2 Issues)
|
|
|
|
critical 🚨 5 | medium |
low 🔷 2 |
🔍 Enhanced Analysis of Dependency Behaviors During Installation
🚨 Critical severity - Detected Issues and Actionable Insights
🔎🔀
2 categories
🔎🔀 | 2 categories |
-
🔀 Typosquatting Concerns ∙ 3 packages
-
📦 ws@8.14.2
- Issue: Name resembles "ms", "qs" (possible typosquatting).
- Action: Confirm correct package usage.
- Details: 🔗
-
📦 pkg@5.8.1
- Issue: Name resembles "pg", "pug" (possible typosquatting).
- Action: Verify package integrity.
- Details: 🔗
-
📦 @types/ws@8.5.9
- Issue: Name resembles "@types/qs" (possible typosquatting).
- Action: Check for correct package references.
- Details: 🔗
-
⚠️ Medium Severity - Observed Behaviors and Recommendations
📡🔎
2 categories
📡🔎 | 2 categories |
-
📡 Dynamic Instrumentation ∙ 2 packages
-
🔎 Static Analysis ∙ Extended Insights for 14 packages
Detailed analysis and actions for 14 packages with install script concerns.
🔷 Low Severity - Minor Alerts and Observations
📑
1 category
📑 | 1 category |
|
critical 🚨 5 | medium |
low 🔷 2 |
🔍 Enhanced Analysis of Dependency Behaviors During Installation
🚨 Critical severity - Detected Issues and Actionable Insights
🔎🔀
2 categories
🔎🔀 | 2 categories |
-
🔀 Typosquatting Concerns ∙ 3 packages
-
📦 ws@8.14.2
- Issue: Name resembles "ms", "qs" (possible typosquatting).
- Action: Confirm correct package usage.
- Details: 🔗
-
📦 pkg@5.8.1
- Issue: Name resembles "pg", "pug" (possible typosquatting).
- Action: Verify package integrity.
- Details: 🔗
-
📦 @types/ws@8.5.9
- Issue: Name resembles "@types/qs" (possible typosquatting).
- Action: Check for correct package references.
- Details: 🔗
-
⚠️ Medium Severity - Observed Behaviors and Recommendations
📡🔎
2 categories
📡🔎 | 2 categories |
-
📡 Dynamic Instrumentation ∙ 2 packages
-
🔎 Static Analysis ∙ Extended Insights for 14 packages
Detailed analysis and actions for 14 packages with install script concerns.
🔷 Low Severity - Minor Alerts and Observations
📑
1 category
📑 | 1 category |
-
📑 Metadata Considerations ∙ 2 packages
Powered by listen.dev
No description provided.