| Block |
 |
High CVE: npm path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters
CVE: GHSA-37ch-88jc-xwx2 path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters (HIGH)
Affected versions: < 0.1.13
Patched version: 0.1.13
From: package-lock.json → npm/express@4.21.2 → npm/path-to-regexp@0.1.12
ℹ Read more on: This package | This alert | What is a CVE?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/path-to-regexp@0.1.12. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @babel/plugin-syntax-async-generators was last published 6 years ago
Last Publish: 1/13/2020, 9:15:49 PM
From: package-lock.json → npm/jest@29.7.0 → npm/@babel/plugin-syntax-async-generators@7.8.4
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@babel/plugin-syntax-async-generators@7.8.4. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @babel/plugin-syntax-bigint was last published 6 years ago
Last Publish: 1/13/2020, 9:12:19 PM
From: package-lock.json → npm/jest@29.7.0 → npm/@babel/plugin-syntax-bigint@7.8.3
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@babel/plugin-syntax-bigint@7.8.3. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @babel/plugin-syntax-class-properties was last published 5 years ago
Last Publish: 2/3/2021, 1:10:30 AM
From: package-lock.json → npm/jest@29.7.0 → npm/@babel/plugin-syntax-class-properties@7.12.13
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@babel/plugin-syntax-class-properties@7.12.13. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @babel/plugin-syntax-import-meta was last published 6 years ago
Last Publish: 6/30/2020, 1:11:46 PM
From: package-lock.json → npm/jest@29.7.0 → npm/@babel/plugin-syntax-import-meta@7.10.4
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@babel/plugin-syntax-import-meta@7.10.4. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @babel/plugin-syntax-json-strings was last published 6 years ago
Last Publish: 1/13/2020, 9:13:07 PM
From: package-lock.json → npm/jest@29.7.0 → npm/@babel/plugin-syntax-json-strings@7.8.3
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@babel/plugin-syntax-json-strings@7.8.3. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @babel/plugin-syntax-logical-assignment-operators was last published 6 years ago
Last Publish: 6/30/2020, 1:11:47 PM
From: package-lock.json → npm/jest@29.7.0 → npm/@babel/plugin-syntax-logical-assignment-operators@7.10.4
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@babel/plugin-syntax-logical-assignment-operators@7.10.4. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @babel/plugin-syntax-nullish-coalescing-operator was last published 6 years ago
Last Publish: 1/13/2020, 9:14:03 PM
From: package-lock.json → npm/jest@29.7.0 → npm/@babel/plugin-syntax-nullish-coalescing-operator@7.8.3
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@babel/plugin-syntax-nullish-coalescing-operator@7.8.3. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @babel/plugin-syntax-numeric-separator was last published 6 years ago
Last Publish: 6/30/2020, 1:11:49 PM
From: package-lock.json → npm/jest@29.7.0 → npm/@babel/plugin-syntax-numeric-separator@7.10.4
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@babel/plugin-syntax-numeric-separator@7.10.4. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @babel/plugin-syntax-object-rest-spread was last published 6 years ago
Last Publish: 1/13/2020, 9:14:13 PM
From: package-lock.json → npm/jest@29.7.0 → npm/@babel/plugin-syntax-object-rest-spread@7.8.3
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@babel/plugin-syntax-object-rest-spread@7.8.3. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @babel/plugin-syntax-optional-catch-binding was last published 6 years ago
Last Publish: 1/13/2020, 9:14:30 PM
From: package-lock.json → npm/jest@29.7.0 → npm/@babel/plugin-syntax-optional-catch-binding@7.8.3
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@babel/plugin-syntax-optional-catch-binding@7.8.3. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @babel/plugin-syntax-optional-chaining was last published 6 years ago
Last Publish: 1/13/2020, 9:14:43 PM
From: package-lock.json → npm/jest@29.7.0 → npm/@babel/plugin-syntax-optional-chaining@7.8.3
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@babel/plugin-syntax-optional-chaining@7.8.3. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Filesystem access: npm @cspotcode/source-map-support with module fs
Module: fs
Location: Package overview
From: package-lock.json → npm/ts-node@10.9.2 → npm/@cspotcode/source-map-support@0.8.1
ℹ Read more on: This package | This alert | What is filesystem access?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: If a package must read the file system, clarify what it will read and ensure it reads only what it claims to. If appropriate, packages can leave file system access to consumers and operate on data passed to it instead.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@cspotcode/source-map-support@0.8.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Filesystem access: npm @istanbuljs/load-nyc-config with module fs
Module: fs
Location: Package overview
From: package-lock.json → npm/jest@29.7.0 → npm/@istanbuljs/load-nyc-config@1.1.0
ℹ Read more on: This package | This alert | What is filesystem access?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: If a package must read the file system, clarify what it will read and ensure it reads only what it claims to. If appropriate, packages can leave file system access to consumers and operate on data passed to it instead.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@istanbuljs/load-nyc-config@1.1.0. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @istanbuljs/load-nyc-config was last published 6 years ago
Last Publish: 5/20/2020, 3:44:39 PM
From: package-lock.json → npm/jest@29.7.0 → npm/@istanbuljs/load-nyc-config@1.1.0
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@istanbuljs/load-nyc-config@1.1.0. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm @sideway/pinpoint was last published 6 years ago
Last Publish: 10/24/2020, 6:53:39 AM
From: package-lock.json → npm/joi@17.13.3 → npm/@sideway/pinpoint@2.0.0
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@sideway/pinpoint@2.0.0. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm array-flatten was last published 6 years ago
Last Publish: 11/21/2019, 5:14:39 AM
From: package-lock.json → npm/express@4.21.2 → npm/array-flatten@1.1.1
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/array-flatten@1.1.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Filesystem access: npm babel-plugin-istanbul with module fs
Module: fs
Location: Package overview
From: package-lock.json → npm/jest@29.7.0 → npm/babel-plugin-istanbul@6.1.1
ℹ Read more on: This package | This alert | What is filesystem access?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: If a package must read the file system, clarify what it will read and ensure it reads only what it claims to. If appropriate, packages can leave file system access to consumers and operate on data passed to it instead.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/babel-plugin-istanbul@6.1.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm basic-auth was last published 8 years ago
Last Publish: 9/20/2018, 3:26:02 AM
From: package-lock.json → npm/morgan@1.10.1 → npm/basic-auth@2.0.1
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/basic-auth@2.0.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm bintrees was last published 9 years ago
Last Publish: 8/5/2017, 7:08:36 PM
From: package-lock.json → npm/prom-client@15.1.3 → npm/bintrees@1.0.2
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/bintrees@1.0.2. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm bser was last published 7 years ago
Last Publish: 10/22/2019, 4:20:14 PM
From: package-lock.json → npm/jest@29.7.0 → npm/bser@2.1.1
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/bser@2.1.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm buffer-equal-constant-time was last published 12 years ago
Last Publish: 12/16/2013, 8:12:17 PM
From: package-lock.json → npm/jsonwebtoken@9.0.3 → npm/buffer-equal-constant-time@1.0.1
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/buffer-equal-constant-time@1.0.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm co was last published 11 years ago
Last Publish: 7/9/2015, 10:30:44 PM
From: package-lock.json → npm/jest@29.7.0 → npm/co@4.6.0
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/co@4.6.0. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm compressible was last published 6 years ago
Last Publish: 1/6/2020, 4:50:09 AM
From: package-lock.json → npm/compression@1.8.1 → npm/compressible@2.0.18
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/compressible@2.0.18. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Filesystem access: npm concurrently with module fs
Module: fs
Location: Package overview
From: package-lock.json → npm/concurrently@9.2.1
ℹ Read more on: This package | This alert | What is filesystem access?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: If a package must read the file system, clarify what it will read and ensure it reads only what it claims to. If appropriate, packages can leave file system access to consumers and operate on data passed to it instead.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/concurrently@9.2.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Filesystem access: npm create-require with module fs
Module: fs
Location: Package overview
From: package-lock.json → npm/ts-node@10.9.2 → npm/create-require@1.1.1
ℹ Read more on: This package | This alert | What is filesystem access?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: If a package must read the file system, clarify what it will read and ensure it reads only what it claims to. If appropriate, packages can leave file system access to consumers and operate on data passed to it instead.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/create-require@1.1.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
| Warn |
 |
Unmaintained: npm create-require was last published 5 years ago
Last Publish: 11/26/2020, 1:41:32 PM
From: package-lock.json → npm/ts-node@10.9.2 → npm/create-require@1.1.1
ℹ Read more on: This package | This alert | What are unmaintained packages?
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Package should publish periodic maintenance releases if they are maintained, or deprecate if they have no intention in further maintenance.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/create-require@1.1.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
|
|
See 45 more rows in the dashboard
|