NPM package dependencies, supply chain security analysis (Socket) #2103
danielweck
started this conversation in
Developer corner
Replies: 2 comments
-
Too many "medium" alerts to list here (178, some direct, most transitive), all marked as "supply chain risk" by Socket (system shell, network access, eval, and a few other criteria match) |
Beta Was this translation helpful? Give feedback.
0 replies
-
Latest NPM package updates on the |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
FYI, no immediate action needed.
https://socket.dev/dashboard/org/gh/edrlab/repo/thorium-reader
svg-sprite-loader
->svg-baker
->traverse
r2-utils-js
->unzipper
->buffers
r2-utils-js
->unzipper
->chainsaw
->traverse
npm ls --all
Beta Was this translation helpful? Give feedback.
All reactions