Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Version Packages #512

Merged
merged 1 commit into from
Jun 10, 2024
Merged

Version Packages #512

merged 1 commit into from
Jun 10, 2024

Conversation

github-actions[bot]
Copy link
Contributor

@github-actions github-actions bot commented Jun 6, 2024

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@replayio/[email protected]

Patch Changes

@replayio/[email protected]

Patch Changes

@replayio/[email protected]

Patch Changes

@replayio/[email protected]

Patch Changes

[email protected]

Patch Changes

  • #439 75ee1cb Thanks @bvaughn! - Show the reason for recordings failures if it is known (e.g. a stack overflow)

@replayio/[email protected]

Patch Changes

  • #516 c27e2af Thanks @Andarist! - Fixed a race condition that could cause some tests not being added correctly to a test run

Copy link

socket-security bot commented Jun 6, 2024

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package Note
Install scripts npm/@replayio/[email protected]
  • Install script: postinstall
  • Source: "$npm_node_execpath" ./first-run.js
Install scripts npm/@replayio/[email protected]
  • Install script: postinstall
  • Source: node ./first-run.js

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/[email protected] or ignore all packages with @SocketSecurity ignore-all

@github-actions github-actions bot force-pushed the changeset-release/main branch 2 times, most recently from 34acf6b to a661e11 Compare June 7, 2024 14:50
@github-actions github-actions bot force-pushed the changeset-release/main branch from a661e11 to 8e6fa52 Compare June 10, 2024 16:12
@markerikson
Copy link
Contributor

Doesn't look like the Changesets comment bot updated the comment with my sourcemap-upload changes, but I see the force-push to update vs main and I see the relevant changes in here.

@Andarist stamped, so I'm going to merge and release these.

@markerikson markerikson merged commit be12c69 into main Jun 10, 2024
1 of 2 checks passed
@markerikson markerikson deleted the changeset-release/main branch June 10, 2024 18:15
@Andarist
Copy link
Member

FWIW, it didn't get updated because that workflow run hit a secondary rate limit when querying GitHub's API. This seems to happen more often lately 😢

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants