Skip to content

Bump pillow from 8.1.1 to 10.3.0 in /src #28

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 26 commits into
base: Current
Choose a base branch
from

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Apr 3, 2024

Bumps pillow from 8.1.1 to 10.3.0.

Release notes

Sourced from pillow's releases.

10.3.0

https://pillow.readthedocs.io/en/stable/releasenotes/10.3.0.html

Changes

... (truncated)

Changelog

Sourced from pillow's changelog.

10.3.0 (2024-04-01)

  • CVE-2024-28219: Use strncpy to avoid buffer overflow #7928 [radarhere, hugovk]

  • Deprecate eval(), replacing it with lambda_eval() and unsafe_eval() #7927 [radarhere, hugovk]

  • Raise ValueError if seeking to greater than offset-sized integer in TIFF #7883 [radarhere]

  • Add --report argument to __main__.py to omit supported formats #7818 [nulano, radarhere, hugovk]

  • Added RGB to I;16, I;16L, I;16B and I;16N conversion #7918, #7920 [radarhere]

  • Fix editable installation with custom build backend and configuration options #7658 [nulano, radarhere]

  • Fix putdata() for I;16N on big-endian #7209 [Yay295, hugovk, radarhere]

  • Determine MPO size from markers, not EXIF data #7884 [radarhere]

  • Improved conversion from RGB to RGBa, LA and La #7888 [radarhere]

  • Support FITS images with GZIP_1 compression #7894 [radarhere]

  • Use I;16 mode for 9-bit JPEG 2000 images #7900 [scaramallion, radarhere]

  • Raise ValueError if kmeans is negative #7891 [radarhere]

  • Remove TIFF tag OSUBFILETYPE when saving using libtiff #7893 [radarhere]

  • Raise ValueError for negative values when loading P1-P3 PPM images #7882 [radarhere]

  • Added reading of JPEG2000 palettes #7870 [radarhere]

  • Added alpha_quality argument when saving WebP images #7872 [radarhere]

... (truncated)

Commits
  • 5c89d88 10.3.0 version bump
  • 63cbfcf Update CHANGES.rst [ci skip]
  • 2776126 Merge pull request #7928 from python-pillow/lcms
  • aeb51cb Merge branch 'main' into lcms
  • 5beb0b6 Update CHANGES.rst [ci skip]
  • cac6ffa Merge pull request #7927 from python-pillow/imagemath
  • f5eeeac Name as 'options' in lambda_eval and unsafe_eval, but '_dict' in deprecated eval
  • facf3af Added release notes
  • 2a93aba Use strncpy to avoid buffer overflow
  • a670597 Update CHANGES.rst [ci skip]
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Apr 3, 2024
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/combined-stream@1.0.8 None 0 11.5 kB alexindigo
npm/commander@2.20.0 filesystem, shell 0 62.2 kB abetomo
npm/common-tags@1.8.0 None 0 226 kB fatfisz
npm/commondir@1.0.1 None 0 4.79 kB substack
npm/compare-versions@3.5.1 None 0 21.5 kB omichelsen
npm/component-bind@1.0.0 None 0 2.43 kB tootallnate
npm/component-emitter@1.3.0 None 0 8 kB nami-doc
npm/component-inherit@0.0.3 None 0 1.65 kB coreh
npm/compose-function@3.0.3 None 0 7.33 kB schtoeffel
npm/compressible@2.0.18 None 0 7.36 kB dougwilson
npm/compression@1.7.4 None 0 23.3 kB dougwilson
npm/concat-map@0.0.1 None 0 4.86 kB substack
npm/concat-stream@1.6.2 None 0 9.56 kB mafintosh
npm/confusing-browser-globals@1.0.9 None 0 3.87 kB iansu
npm/connect-history-api-fallback@1.6.0 None 0 11.5 kB bripkens
npm/console-browserify@1.1.0 None 0 8.46 kB raynos
npm/console-control-strings@1.1.0 None 0 12.7 kB iarna
npm/constants-browserify@1.0.0 None 0 7.46 kB juliangruber
npm/contains-path@0.1.0 None 0 5.1 kB jonschlinkert
npm/content-disposition@0.5.3 None 0 19.1 kB dougwilson
npm/content-type@1.0.4 None 0 10.2 kB dougwilson
npm/convert-source-map@1.6.0 filesystem 0 10.5 kB thlorenz
npm/cookie-signature@1.0.6 None 0 3.94 kB natevw
npm/cookie@0.4.0 None 0 17.9 kB dougwilson
npm/copy-concurrently@1.0.5 filesystem 0 21.5 kB iarna
npm/copy-descriptor@0.1.1 None 0 4.15 kB jonschlinkert
npm/copy-props@2.0.4 None 0 14 kB sttk
npm/core-js-compat@3.6.4 None 0 300 kB zloirock
npm/core-js@3.6.4 environment, eval, filesystem 0 664 kB zloirock
npm/core-util-is@1.0.2 None 0 23.2 kB isaacs
npm/cosmiconfig@5.2.1 filesystem 0 43.4 kB davidtheclark
npm/create-ecdh@4.0.3 None 0 5.4 kB cwmma
npm/create-hash@1.2.0 None 0 5.21 kB cwmma
npm/create-hmac@1.1.7 None 0 5.81 kB cwmma
npm/cross-spawn@6.0.5 environment, filesystem, shell 0 21.4 kB satazor
npm/crypto-browserify@3.12.0 None 0 53.5 kB cwmma
npm/css-blank-pseudo@0.1.4 None 0 64 kB jonathantneal
npm/css-color-names@0.0.4 None 0 5.33 kB bahamas10
npm/css-declaration-sorter@4.0.1 filesystem 0 29.3 kB siilwyn
npm/css-has-pseudo@0.10.0 None 0 56.4 kB jonathantneal
npm/css-loader@1.0.1 None 0 41.7 kB evilebottnawi
npm/css-modules-loader-core@1.1.0 None 0 13.7 kB geelen
npm/css-prefers-color-scheme@3.1.1 None 0 40.9 kB jonathantneal
npm/css-select-base-adapter@0.1.1 None 0 10.9 kB nrkn
npm/css-select@2.1.0 None 0 53.7 kB feedic
npm/css-selector-tokenizer@0.7.1 None 0 17.1 kB sokra
npm/css-tree@1.0.0-alpha.37 None 0 995 kB lahmatiy
npm/css-what@2.1.3 None 0 10.6 kB feedic
npm/css.escape@1.5.1 None 0 6.49 kB mathias
npm/css@2.2.4 filesystem 0 35.3 kB slexaxton
npm/cssdb@4.4.0 None 0 40.6 kB jonathantneal
npm/cssesc@0.1.0 None 0 19 kB mathias
npm/cssnano-preset-default@4.0.7 None 0 20.5 kB evilebottnawi
npm/cssnano-util-get-arguments@4.0.0 None 0 2.63 kB evilebottnawi
npm/cssnano-util-get-match@4.0.0 None 0 2.65 kB evilebottnawi
npm/cssnano-util-raw-cache@4.0.1 None 0 2.86 kB ai
npm/cssnano-util-same-parent@4.0.1 None 0 2.86 kB ai
npm/cssnano@4.1.10 None 0 29.5 kB evilebottnawi
npm/csso@4.0.2 None 0 845 kB lahmatiy
npm/cssom@0.3.8 None 0 49 kB nv
npm/cssstyle@1.4.0 None 0 206 kB jon.sakas
npm/csstype@2.6.8 None 0 1.66 MB faddee
npm/cyclist@0.2.2 None 0 2.26 kB mafintosh
npm/d@1.0.1 None 0 22.8 kB medikoo
npm/damerau-levenshtein@1.0.6 None 0 11.4 kB lazurski
npm/dashdash@1.14.1 environment, filesystem 0 80.6 kB trentm
npm/data-urls@1.1.0 None 0 8.04 kB domenic
npm/date-now@0.1.4 None 0 4.73 kB raynos
npm/debug-fabulous@1.1.0 None 0 78.8 kB nmccready
npm/debug@4.1.1 environment 0 81.5 kB qix
npm/decamelize@1.2.0 None 0 2.94 kB sindresorhus
npm/decode-uri-component@0.2.0 None 0 5.71 kB samverschueren
npm/decompress-response@4.2.1 None 0 5.26 kB sindresorhus
npm/deep-equal@1.1.1 None 0 26.4 kB ljharb
npm/deep-extend@0.6.0 None 0 9.19 kB unclechu
npm/deep-is@0.1.3 None 0 8.22 kB thlorenz
npm/default-compare@1.0.0 None 0 6.99 kB doowb
npm/default-gateway@4.2.0 None 0 14.9 kB silverwind
npm/default-resolution@2.0.0 None 0 5.18 kB phated
npm/define-properties@1.1.3 None 0 23 kB ljharb
npm/define-property@2.0.2 None 0 10.7 kB doowb
npm/del@4.1.1 None 0 9.04 kB sindresorhus
npm/delayed-stream@1.0.0 None 0 8.02 kB apechimp
npm/delegates@1.0.0 None 0 7.46 kB tjholowaychuk
npm/denodeify@1.2.1 None 0 9.8 kB mattandrews
npm/depd@1.1.2 environment, eval 0 30.5 kB dougwilson
npm/des.js@1.0.0 None 0 38.7 kB indutny
npm/destroy@1.0.4 filesystem 0 5.2 kB dougwilson
npm/detect-file@1.0.0 filesystem 0 8.63 kB doowb
npm/detect-libc@1.0.3 environment, filesystem, shell 0 17.2 kB lovell
npm/detect-newline@2.1.0 None 0 3.1 kB sindresorhus
npm/detect-node@2.0.4 None 0 2.55 kB iliakan
npm/detect-port-alt@1.1.6 network 0 31.5 kB timer
npm/diagnostic-channel-publishers@0.2.1 None 0 30.7 kB jackhorton
npm/diagnostic-channel@0.2.0 unsafe 0 17.3 kB jackhorton
npm/diff-sequences@24.9.0 None 0 54.1 kB scotthovestadt
npm/diff@3.5.0 None 0 622 kB kpdecker
npm/diffie-hellman@5.0.3 None 0 17.3 kB cwmma
npm/dir-glob@2.0.0 None 0 4.62 kB kevva
npm/dns-equal@1.0.0 None 0 3.18 kB watson
npm/dns-packet@1.3.1 None 0 28.2 kB silverwind
npm/dns-txt@2.0.2 None 0 11.6 kB watson
npm/doctrine@3.0.0 None 0 106 kB eslint
npm/dom-converter@0.2.0 None 0 7.9 kB ariaminaei
npm/dom-serializer@0.1.1 None 0 4.69 kB feedic
npm/domain-browser@1.2.0 None 0 16.8 kB bevryme
npm/domelementtype@1.3.1 None 0 2.07 kB feedic
npm/domexception@1.0.1 None 0 14.5 kB domenic
npm/domhandler@2.4.2 None 0 29.9 kB feedic
npm/domutils@1.7.0 None 0 20.5 kB feedic
npm/dot-case@3.0.3 None 0 10.4 kB blakeembrey
npm/dot-prop@5.2.0 None 0 9.42 kB sindresorhus
npm/dotenv-expand@5.1.0 None 0 15.9 kB motdotla
npm/dotenv@8.2.0 environment, filesystem 0 23.1 kB maxbeatty
npm/duplexer@0.1.1 None 0 5.53 kB raynos
npm/duplexify@3.7.1 None 0 17.1 kB mafintosh
npm/each-props@1.3.2 None 0 7.96 kB sttk
npm/ecc-jsbn@0.1.2 None 0 27.8 kB aduh95
npm/ee-first@1.1.1 None 0 6.26 kB dougwilson
npm/electron-to-chromium@1.3.355 None 0 39.4 kB kilianvalkhof
npm/elliptic@6.5.4 None 0 118 kB indutny
npm/emoji-regex@7.0.3 None 0 36.3 kB mathias
npm/emojis-list@2.1.0 None 0 42.1 kB kikobeats
npm/encodeurl@1.0.2 None 0 7.86 kB dougwilson
npm/end-of-stream@1.4.1 None 0 5.87 kB mafintosh
npm/engine.io-client@3.5.1 None 0 180 kB darrachequesne
npm/engine.io-parser@2.2.1 None 0 39.2 kB darrachequesne
npm/engine.io@3.5.0 environment, network 0 71 kB darrachequesne
npm/enhanced-resolve@4.1.0 None 0 87.3 kB sokra
npm/entities@1.1.2 None 0 57.4 kB feedic
npm/errno@0.1.7 None 0 18 kB ralphtheninja
npm/error-ex@1.3.2 None 0 9.04 kB qix
npm/es-abstract@1.13.0 None 0 282 kB ljharb
npm/es-to-primitive@1.2.0 None 0 49.8 kB ljharb
npm/es5-ext@0.10.50 eval 0 531 kB medikoo
npm/es6-iterator@2.0.3 None 0 29.7 kB medikoo
npm/es6-promise@4.2.8 None 0 315 kB stefanpenner
npm/es6-promisify@5.0.0 None 0 7.76 kB digitaldesignlabs
npm/es6-symbol@3.1.1 None 0 15.3 kB medikoo
npm/es6-weak-map@2.0.3 None 0 12.5 kB medikoo
npm/escape-html@1.0.3 None 0 3.66 kB dougwilson
npm/escape-string-regexp@1.0.5 None 0 2.69 kB jbnicolai
npm/escodegen@1.11.1 None 0 106 kB michaelficarra
npm/eslint-config-react-app@5.2.0 None 0 16.4 kB iansu
npm/eslint-import-resolver-node@0.3.3 None 0 6.38 kB ljharb
npm/eslint-loader@3.0.3 filesystem 0 35.2 kB ricardogobbosouza
npm/eslint-module-utils@2.5.2 None 0 24.6 kB ljharb
npm/eslint-plugin-flowtype@4.6.0 None 0 284 kB gajus
npm/eslint-plugin-import@2.20.0 filesystem, unsafe 0 868 kB ljharb
npm/eslint-plugin-jsx-a11y@6.2.3 None 0 587 kB jessebeach
npm/eslint-plugin-react-hooks@1.7.0 environment 0 102 kB acdlite
npm/eslint-plugin-react@7.18.0 None 0 685 kB ljharb
npm/eslint-scope@4.0.3 None 0 77 kB eslint
npm/eslint-utils@1.4.3 None 0 314 kB mysticatea
npm/eslint-visitor-keys@1.1.0 None 0 23.3 kB eslint
npm/eslint@6.8.0 filesystem, unsafe 0 2.9 MB eslintbot
npm/espree@6.1.2 None 0 67 kB eslintbot
npm/esprima@4.0.1 None 0 314 kB ariya
npm/esquery@1.1.0 None 0 95.1 kB michaelficarra
npm/esrecurse@4.2.1 None 0 13.5 kB michaelficarra
npm/estraverse@4.2.0 None 0 33 kB nzakas
npm/esutils@2.0.2 None 0 49.3 kB michaelficarra
npm/etag@1.8.1 filesystem 0 10.8 kB dougwilson
npm/event-emitter@0.3.5 None 0 27.2 kB medikoo
npm/event-stream@4.0.1 None 0 46.9 kB right9ctrl
npm/eventemitter2@5.0.1 None 0 40.2 kB rangermauve
npm/eventemitter3@4.0.0 None 0 37 kB lpinca
npm/events@3.0.0 None 0 72 kB goto-bus-stop
npm/eventsource@1.0.7 network 0 445 kB rexxars
npm/evp_bytestokey@1.0.3 None 0 5.13 kB dcousens
npm/exec-sh@0.3.2 shell 0 23 kB tsertkov
npm/execa@1.0.0 environment, shell 0 19.9 kB sindresorhus
npm/exit@0.1.2 None 0 59.8 kB cowboy
npm/expand-brackets@2.1.4 None 0 26 kB jonschlinkert
npm/expand-template@2.0.3 None 0 5.41 kB ralphtheninja
npm/expand-tilde@2.0.2 None 0 6.59 kB doowb
npm/expect@25.1.0 None 0 2.07 MB davidzilburg
npm/express@4.17.1 environment, filesystem, network 0 208 kB dougwilson
npm/extend-shallow@3.0.2 None 0 8.61 kB phated
npm/extend@3.0.2 None 0 23.5 kB ljharb
npm/external-editor@3.1.0 environment, filesystem, shell 0 27 kB mrkmg
npm/extglob@2.0.4 None 0 41.1 kB jonschlinkert
npm/extsprintf@1.3.0 None 0 22.8 kB dap
npm/fancy-log@1.3.3 None 0 6.49 kB phated
npm/fast-deep-equal@2.0.1 None 0 5.42 kB esp
npm/fast-glob@2.2.7 None 0 126 kB mrmlnc
npm/fast-json-stable-stringify@2.0.0 None 0 16.1 kB esp
npm/fast-levenshtein@2.0.6 None 0 9.44 kB hiddentao
npm/fastparse@1.1.2 None 0 7.84 kB sokra
npm/faye-websocket@0.10.0 network 0 36.3 kB jcoglan
npm/fb-watchman@2.0.0 environment, network, shell 0 10.8 kB wez
npm/fd-slicer@1.1.0 filesystem 0 29.8 kB thejoshwolfe
npm/figgy-pudding@3.5.1 None 0 18.6 kB zkat
npm/figures@3.2.0 None 0 12.1 kB sindresorhus
npm/file-entry-cache@5.0.1 filesystem 0 24.5 kB royriojas
npm/file-loader@4.3.0 None 0 33 kB evilebottnawi
npm/file-uri-to-path@1.0.0 None 0 8.07 kB tootallnate
npm/filesize@6.0.1 None 0 64.8 kB avoidwork
npm/fill-range@4.0.0 None 0 16.9 kB jonschlinkert
npm/finalhandler@1.1.2 environment 0 17 kB dougwilson
npm/find-cache-dir@2.1.0 None 0 5.38 kB sindresorhus
npm/find-up@3.0.0 None 0 4.84 kB sindresorhus
npm/findup-sync@2.0.0 filesystem 0 5.49 kB phated
npm/fined@1.2.0 filesystem 0 8.66 kB phated
npm/flagged-respawn@1.0.1 shell 0 10.4 kB phated
npm/flat-cache@2.0.1 filesystem 0 29.1 kB royriojas
npm/flat@4.1.0 None 0 20.7 kB timoxley
npm/flatted@2.0.1 None 0 20.9 kB webreflection
npm/flatten@1.0.3 None 0 3.68 kB mk-pmb
npm/flush-write-stream@1.1.1 None 0 6.5 kB mafintosh
npm/follow-redirects@1.10.0 network 0 23.2 kB rubenverborgh
npm/for-in@1.0.2 None 0 6.28 kB jonschlinkert
npm/for-own@0.1.5 None 0 6.47 kB jonschlinkert
npm/forever-agent@0.6.1 network 0 14 kB simov
npm/fork-ts-checker-webpack-plugin@3.1.1 environment, filesystem, shell, unsafe 0 264 kB piotr-oles
npm/form-data@2.3.3 filesystem, network 0 119 kB alexindigo
npm/forwarded@0.1.2 None 0 5.55 kB dougwilson
npm/fragment-cache@0.2.1 None 0 9.9 kB jonschlinkert
npm/fresh@0.5.2 None 0 10.1 kB dougwilson
npm/from@0.1.7 None 0 8.49 kB dominictarr
npm/from2@2.3.0 None 0 9.35 kB mafintosh
npm/fs-constants@1.0.0 filesystem 0 2.22 kB mafintosh
npm/fs-extra@8.1.0 filesystem 0 128 kB ryanzim
npm/fs-minipass@2.1.0 filesystem 0 14.1 kB isaacs
npm/fs-mkdirp-stream@1.0.0 None 0 7.67 kB phated
npm/fs-write-stream-atomic@1.0.10 None 0 18.7 kB iarna
npm/fs.realpath@1.0.0 environment, filesystem 0 13.4 kB isaacs
npm/fsevents@1.2.9 environment, filesystem, shell 0 1.92 MB pipobscure
npm/function-bind@1.1.1 None 0 25.2 kB ljharb
npm/functional-red-black-tree@1.0.1 None 0 43.5 kB mikolalysenko
npm/gauge@2.7.4 None 0 48.3 kB iarna
npm/generic-names@1.0.3 None 0 3.88 kB sullenor
npm/gensync@1.0.0-beta.1 None 0 28.3 kB loganfsmyth
npm/get-caller-file@1.0.3 None 0 2.48 kB stefanpenner
npm/get-own-enumerable-property-symbols@3.0.2 None 0 4.7 kB mightyiam
npm/get-stream@4.1.0 None 0 7.88 kB sindresorhus
npm/get-value@2.0.6 None 0 3.71 kB jonschlinkert
npm/getpass@0.1.7 filesystem 0 5.67 kB arekinath
npm/git-rev-sync@1.12.0 shell 0 13.4 kB kurttheviking
npm/github-from-package@0.0.0 None 0 4.61 kB substack
npm/glob-parent@3.1.0 None 0 6.04 kB es128
npm/glob-stream@6.1.0 None 0 12.2 kB phated
npm/glob-to-regexp@0.3.0 None 0 17.6 kB nickfitzgerald
npm/glob-watcher@5.0.3 None 0 11.1 kB phated
npm/glob@7.1.4 filesystem 0 56 kB isaacs
npm/global-modules@2.0.0 environment 0 6.57 kB jonschlinkert
npm/global-prefix@3.0.0 environment, filesystem 0 8.27 kB jonschlinkert
npm/globals@11.12.0 None 0 39.8 kB sindresorhus
npm/globby@8.0.2 filesystem 0 12.4 kB sindresorhus
npm/glogg@1.0.2 None 0 6.09 kB phated
npm/graceful-fs@4.1.15 environment, filesystem 0 25.9 kB isaacs
npm/growl@1.10.5 environment, filesystem, shell 0 59.3 kB deiga
npm/growly@1.3.0 filesystem, network 0 49.4 kB theabraham
npm/gulp-cli@2.2.0 environment, filesystem, network, unsafe 0 58 kB phated
npm/gulp-filter@5.1.0 None 0 7.06 kB sindresorhus
npm/gulp-sourcemaps@2.6.5 None 0 35.4 kB nmccready
npm/gulp-typescript@5.0.1 None 0 80.5 kB ivogabe
npm/gulp@4.0.2 None 0 20.9 kB phated
npm/gulplog@1.0.0 None 0 4.23 kB phated
npm/gzip-size@5.1.1 filesystem 0 7.48 kB sindresorhus
npm/handle-thing@2.0.0 None 0 11.6 kB daviddias
npm/har-schema@2.0.0 None 0 15.1 kB ahmadnassri
npm/har-validator@5.1.3 None 0 8.23 kB ahmadnassri
npm/harmony-reflect@1.6.1 None 0 88.7 kB tvcutsem
npm/has-ansi@2.0.0 None 0 3.1 kB sindresorhus
npm/has-binary2@1.0.3 None 0 5.01 kB darrachequesne
npm/has-cors@1.1.0 None 0 2.71 kB shtylman
npm/has-symbols@1.0.0 None 0 14 kB ljharb
npm/has-unicode@2.0.1 environment 0 3.44 kB iarna
npm/has-value@1.0.0 None 0 7.62 kB jonschlinkert
npm/has-values@1.0.0 None 0 7.88 kB jonschlinkert
npm/has@1.0.3 None 0 2.77 kB ljharb
npm/hash-base@3.0.4 None 0 6.03 kB dcousens
npm/hash.js@1.1.7 None 0 41.7 kB indutny
npm/he@1.2.0 None 0 124 kB mathias
npm/hex-color-regex@1.1.0 None 0 22.6 kB tunnckocore
npm/hmac-drbg@1.0.1 None 0 25 kB indutny
npm/hoist-non-react-statics@3.3.0 None 0 17.4 kB mridgway
npm/homedir-polyfill@1.0.3 environment, filesystem 0 8.05 kB doowb
npm/hosted-git-info@2.8.9 None 0 25.8 kB nlf
npm/hpack.js@2.1.6 None 0 86.9 kB indutny
npm/hsl-regex@1.0.0 None 0 4.66 kB johno
npm/hsla-regex@1.0.0 None 0 4.78 kB johno
npm/html-comment-regex@1.1.2 None 0 2.97 kB stevemao
npm/html-encoding-sniffer@1.0.2 None 0 11.3 kB domenic
npm/html-entities@1.2.1 None 0 63.5 kB mdevils
npm/html-escaper@2.0.0 None 0 12.6 kB webreflection
npm/html-minifier-terser@5.0.4 None 0 96.9 kB danielruf
npm/html-webpack-plugin@4.0.0-beta.11 filesystem, unsafe 0 110 kB jantimon
npm/htmlparser2@3.10.1 network 0 55 kB feedic
npm/http-deceiver@1.2.7 None 0 13.9 kB indutny
npm/http-errors@1.7.2 None 0 17.1 kB dougwilson
npm/http-parser-js@0.4.10 None 0 19 kB jimbly
npm/http-proxy-agent@2.1.0 network 0 20.9 kB tootallnate
npm/http-proxy-middleware@0.19.1 network 0 47.7 kB chimurai
npm/http-proxy@1.18.1 network 0 232 kB jcrugzz
npm/http-signature@1.2.0 network 0 48.4 kB arekinath
npm/https-browserify@1.0.0 network 0 2.79 kB feross
npm/https-proxy-agent@2.2.4 network 0 19.5 kB tootallnate
npm/human-signals@1.1.1 None 0 42.4 kB ehmicky
npm/iconv-lite@0.4.24 None 0 336 kB ashtuchkin
npm/icss-replace-symbols@1.1.0 None 0 3.03 kB geelen
npm/icss-utils@2.1.0 None 0 8.4 kB trysound
npm/identity-obj-proxy@3.0.0 None 0 8.38 kB keyanzhang
npm/ieee754@1.1.13 None 0 6.25 kB feross
npm/iferr@0.1.5 None 0 5.43 kB nadav
npm/ignore@4.0.6 None 0 37.8 kB kael
npm/image-size@0.5.5 filesystem 0 19.2 kB netroy
npm/immer@1.10.0 None 0 247 kB aleclarson
npm/import-cwd@2.1.0 None 0 3.55 kB sindresorhus
npm/import-fresh@2.0.0 None 0 3.9 kB sindresorhus
npm/import-from@2.1.0 None 0 3.73 kB sindresorhus
npm/import-local@2.0.0 None 0 3.6 kB sindresorhus
npm/imurmurhash@0.1.4 None 0 11.9 kB jensyt
npm/indent-string@4.0.0 None 0 4.4 kB sindresorhus
npm/indexes-of@1.0.1 None 0 2.73 kB dominictarr
npm/indexof@0.0.1 None 0 909 B
npm/infer-owner@1.0.4 filesystem 0 4.29 kB isaacs
npm/inflight@1.0.6 None 0 3.76 kB isaacs
npm/inherits@2.0.3 None 0 3.82 kB isaacs
npm/ini@1.3.8 None 0 9.3 kB isaacs
npm/inquirer@7.0.4 None 0 78.1 kB sboudrias
npm/internal-ip@4.3.0 None 0 5.73 kB sindresorhus
npm/interpret@1.2.0 None 0 14.5 kB phated
npm/intl-format-cache@4.1.13 None 0 20.5 kB longlho
npm/intl-locales-supported@1.4.5 None 0 13.3 kB longlho
npm/intl-messageformat-parser@3.0.7 None 0 310 kB longlho
npm/intl-messageformat@6.1.9 None 0 606 kB longlho
npm/invariant@2.2.4 None 0 7.64 kB zertosh
npm/invert-kv@2.0.0 None 0 2.38 kB sindresorhus
npm/ip-regex@2.1.0 None 0 4.73 kB sindresorhus
npm/ip@1.1.5 None 0 35.7 kB indutny
npm/ipaddr.js@1.9.0 None 0 42.1 kB whitequark
npm/is-absolute-url@2.1.0 None 0 2.48 kB sindresorhus
npm/is-absolute@1.0.0 None 0 8.55 kB jonschlinkert
npm/is-accessor-descriptor@0.1.6 None 0 7.36 kB jonschlinkert
npm/is-arguments@1.0.4 None 0 19.8 kB ljharb
npm/is-arrayish@0.2.1 None 0 4.05 kB qix
npm/is-binary-path@1.0.1 None 0 2.79 kB sindresorhus
npm/is-buffer@2.0.3 None 0 4.26 kB feross
npm/is-callable@1.1.4 None 0 30.6 kB ljharb
npm/is-ci@2.0.0 None 0 3.58 kB watson
npm/is-color-stop@1.1.0 None 0 9.88 kB pigcan
npm/is-data-descriptor@0.1.4 None 0 6.55 kB jonschlinkert
npm/is-date-object@1.0.1 None 0 15 kB ljharb
npm/is-descriptor@0.1.6 None 0 9.01 kB jonschlinkert
npm/is-directory@0.3.1 filesystem 0 5.79 kB jonschlinkert
npm/is-docker@2.0.0 filesystem 0 2.91 kB sindresorhus
npm/is-extendable@0.1.1 None 0 5.09 kB jonschlinkert
npm/is-extglob@2.1.1 None 0 6.22 kB jonschlinkert
npm/is-fullwidth-code-point@2.0.0 None 0 4.14 kB sindresorhus
npm/is-generator-fn@2.1.0 None 0 3.28 kB sindresorhus
npm/is-generator-function@1.0.7 None 0 24.2 kB ljharb
npm/is-glob@4.0.1 None 0 11.3 kB phated
npm/is-negated-glob@1.0.0 None 0 6.01 kB jonschlinkert
npm/is-number@3.0.0 None 0 7.5 kB jonschlinkert
npm/is-obj@2.0.0 None 0 2.82 kB sindresorhus
npm/is-path-cwd@2.1.0 None 0 2.61 kB sindresorhus
npm/is-path-in-cwd@2.1.0 None 0 2.81 kB sindresorhus
npm/is-path-inside@2.1.0 None 0 3.09 kB sindresorhus
npm/is-plain-obj@1.1.0 None 0 2.62 kB sindresorhus
npm/is-plain-object@2.0.4 None 0 7.5 kB jonschlinkert
npm/is-promise@2.1.0 None 0 2.61 kB forbeslindesay
npm/is-regex@1.0.4 None 0 21.1 kB ljharb
npm/is-regexp@1.0.0 None 0 1.21 kB sindresorhus
npm/is-relative@1.0.0 None 0 6.59 kB jonschlinkert
npm/is-resolvable@1.1.0 None 0 4.21 kB shinnn
npm/is-root@2.1.0 None 0 2.68 kB sindresorhus
npm/is-stream@1.1.0 None 0 3.23 kB sindresorhus
npm/is-string@1.0.5 None 0 15.7 kB ljharb
npm/is-svg@3.0.0 None 0 3.14 kB sindresorhus
npm/is-symbol@1.0.2 None 0 23.3 kB ljharb
npm/is-typedarray@1.0.0 None 0 4.41 kB hughsk
npm/is-unc-path@1.0.0 None 0 6.51 kB jonschlinkert
npm/is-utf8@0.2.1 None 0 4.34 kB wayfind
npm/is-valid-glob@1.0.0 None 0 6.63 kB phated
npm/is-windows@1.0.2 None 0 7.96 kB jonschlinkert
npm/is-wsl@1.1.0 environment, filesystem 0 2.88 kB sindresorhus
npm/is@3.3.0 None 0 57.5 kB ljharb
npm/isarray@1.0.0 None 0 3.89 kB juliangruber
npm/isexe@2.0.0 environment, filesystem 0 11 kB isaacs
npm/isobject@3.0.1 None 0 6.93 kB doowb
npm/isstream@0.1.2 None 0 13.3 kB rvagg
npm/istanbul-lib-coverage@2.0.5 None 0 22.7 kB coreyfarrell
npm/istanbul-lib-instrument@3.3.0 None 0 55.2 kB coreyfarrell
npm/istanbul-lib-report@3.0.0 filesystem 0 37.5 kB coreyfarrell
npm/istanbul-lib-source-maps@4.0.0 filesystem 0 33.5 kB coreyfarrell
npm/istanbul-reports@3.0.0 None 0 283 kB coreyfarrell
npm/jest-changed-files@25.1.0 environment 0 18.2 kB davidzilburg
npm/jest-config@25.1.0 filesystem 0 136 kB davidzilburg
npm/jest-diff@24.9.0 None 0 70.1 kB scotthovestadt
npm/jest-docblock@25.1.0 None 0 9.38 kB davidzilburg
npm/jest-each@25.1.0 None 0 35.5 kB davidzilburg
npm/jest-environment-jsdom-fourteen@1.0.1 None 0 8.74 kB ianschmitz
npm/jest-environment-jsdom@25.1.0 None 0 9.12 kB davidzilburg
npm/jest-environment-node@25.1.0 unsafe 0 7.21 kB davidzilburg
npm/jest-get-type@24.9.0 None 0 3.83 kB scotthovestadt
npm/jest-jasmine2@25.1.0 None 0 150 kB davidzilburg
npm/jest-leak-detector@25.1.0 unsafe 0 5.65 kB davidzilburg
npm/jest-matcher-utils@24.9.0 None 0 20.4 kB scotthovestadt
npm/jest-message-util@24.9.0 filesystem 0 16 kB scotthovestadt
npm/jest-mock@24.9.0 None 0 134 kB scotthovestadt
npm/jest-pnp-resolver@1.2.1 None 0 3.93 kB arcanis
npm/jest-resolve-dependencies@25.1.0 None 0 8.09 kB davidzilburg
npm/jest-resolve@24.9.0 environment, filesystem, unsafe 0 33.6 kB scotthovestadt
npm/jest-runner@25.1.0 environment, unsafe 0 34.5 kB davidzilburg
npm/jest-runtime@25.1.0 filesystem, unsafe 0 64.4 kB davidzilburg
npm/jest-snapshot@25.1.0 eval, filesystem 0 91.7 kB davidzilburg
npm/jest-transform-css@2.0.0 filesystem 0 14.3 kB dferber90
npm/jest-util@24.9.0 environment, filesystem 0 36.7 kB scotthovestadt
npm/jest-validate@25.1.0 None 0 37.9 kB davidzilburg
npm/jest-watch-typeahead@0.4.2 None 0 24.2 kB simenb
npm/jest-watcher@24.9.0 None 0 35 kB scotthovestadt
npm/jest@25.1.0 None 0 3.53 kB davidzilburg
npm/js-tokens@4.0.0 None 0 15.1 kB lydell
npm/js-yaml@3.13.1 eval 0 283 kB vitaly
npm/jsbn@0.1.1 None 0 45.8 kB andyperlitch
npm/jsdom@15.2.1 eval, filesystem, network, shell, unsafe 0 2 MB domenic
npm/jsesc@0.5.0 None 0 28.1 kB mathias
npm/json-parse-better-errors@1.0.2 None 0 6.7 kB zkat
npm/json-schema-traverse@0.4.1 None 0 19.6 kB esp
npm/json-schema@0.2.3 None 0 147 kB kriszyp
npm/json-stable-stringify-without-jsonify@1.0.1 None 0 14.2 kB samn
npm/json-stable-stringify@1.0.1 None 0 13.9 kB substack
npm/json-stringify-safe@5.0.1 None 0 12.7 kB isaacs
npm/json3@3.3.3 None 0 77.1 kB kitcambridge
npm/json5@1.0.1 None 0 88.3 kB jordanbtucker
npm/jsonfile@4.0.0 filesystem 0 16.9 kB ryanzim
npm/jsonify@0.0.0 None 0 14.7 kB
npm/jsprim@1.4.1 None 0 31.1 kB dap
npm/jsx-ast-utils@2.2.3 None 0 195 kB evcohen
npm/just-debounce@1.0.0 None 0 7.13 kB hayes
npm/killable@1.0.1 None 0 2.91 kB commandoline
npm/kind-of@3.2.2 None 0 13.4 kB jonschlinkert
npm/kleur@3.0.3 None 0 9.89 kB lukeed
npm/last-call-webpack-plugin@3.0.0 None 0 11.9 kB nmfr
npm/last-run@1.1.1 None 0 6.46 kB phated
npm/lazy-cache@1.0.4 None 0 7.5 kB jonschlinkert
npm/lazystream@1.0.0 None 0 19.3 kB jpommerening
npm/lcid@2.0.0 None 0 6.37 kB sindresorhus
npm/lead@1.0.0 None 0 5.27 kB phated
npm/left-pad@1.3.0 None 0 9.75 kB stevemao
npm/less-loader@4.1.0 None 0 31 kB michael-ciniawsky
npm/less@3.9.0 eval, filesystem 0 2.67 MB matthew-dean
npm/leven@3.1.0 None 0 5.34 kB sindresorhus
npm/levenary@1.1.1 None 0 4.9 kB tanhauhau
npm/levn@0.3.0 None 0 34 kB gkz
npm/liftoff@3.1.0 environment, filesystem 0 32.5 kB phated
npm/lines-and-columns@1.1.6 None 0 7.08 kB eventualbuddha
npm/linkify-it@2.1.0 None 0 34.4 kB vitaly
npm/load-json-file@4.0.0 None 0 3.21 kB sindresorhus
npm/loader-fs-cache@1.0.2 filesystem 0 6.61 kB viankakrisna
npm/loader-runner@2.4.0 filesystem 0 16.3 kB sokra
npm/loader-utils@1.2.3 None 0 26.9 kB evilebottnawi
npm/locate-path@3.0.0 None 0 3.87 kB sindresorhus
npm/lodash._reinterpolate@3.0.0 None 0 3.18 kB jdalton
npm/lodash.camelcase@4.3.0 None 0 21.9 kB jdalton
npm/lodash.memoize@4.1.2 None 0 20.1 kB jdalton
npm/lodash.sortby@4.7.0 None 0 75.8 kB jdalton
npm/lodash.template@4.5.0 eval 0 50.2 kB jdalton
npm/lodash.templatesettings@4.2.0 eval 0 12.9 kB jdalton
npm/lodash.uniq@4.5.0 None 0 25 kB jdalton
npm/lodash@4.17.21 None 0 1.41 MB bnjmnt4n
npm/log-symbols@2.2.0 environment 0 3.44 kB sindresorhus
npm/loglevel@1.6.7 None 0 134 kB pimterry
npm/lolex@5.1.2 eval 0 136 kB mantoni
npm/loose-envify@1.4.0 environment 0 5.81 kB zertosh
npm/lower-case@2.0.1 None 0 17.5 kB blakeembrey
npm/lru-cache@5.1.1 None 0 15.7 kB isaacs
npm/lru-queue@0.1.0 None 0 5.57 kB medikoo
npm/make-dir@2.1.0 filesystem 0 9.2 kB sindresorhus
npm/make-error@1.3.5 None 0 11.6 kB julien-f
npm/make-iterator@1.0.1 None 0 8.7 kB jonschlinkert
npm/makeerror@1.0.11 None 0 6.07 kB daaku
npm/mamacro@0.0.3 None 0 369 B xtuc
npm/map-age-cleaner@0.1.3 None 0 8.41 kB samverschueren
npm/map-cache@0.2.2 None 0 7.6 kB jonschlinkert
npm/map-stream@0.0.7 None 0 13.6 kB dominictarr
npm/map-visit@1.0.0 None 0 8.47 kB jonschlinkert
npm/markdown-it@8.4.2 None 0 546 kB vitaly
npm/matchdep@2.0.0 None 0 6.65 kB phated
npm/md5.js@1.3.5 None 0 7.67 kB cwmma
npm/mdn-data@2.0.4 None 0 548 kB mdn
npm/mdurl@1.0.1 None 0 22 kB vitaly
npm/media-typer@0.3.0 None 0 11.1 kB dougwilson
npm/mem@4.3.0 None 0 9.75 kB sindresorhus
npm/memoizee@0.4.14 None 0 266 kB medikoo
npm/memory-fs@0.4.1 None 0 13.4 kB sokra
npm/memorystream@0.3.1 None 0 23.2 kB jsbizon
npm/merge-deep@3.0.2 None 0 7.74 kB jonschlinkert
npm/merge-descriptors@1.0.1 None 0 4.89 kB dougwilson
npm/merge2@1.3.0 None 0 8.37 kB zensh
npm/methods@1.1.2 network 0 5.29 kB dougwilson
npm/microevent.ts@0.1.1 None 0 89.5 kB dirtyhairy
npm/micromatch@3.1.10 None 0 84.8 kB jonschlinkert
npm/miller-rabin@4.0.1 None 0 6.84 kB indutny
npm/mime-db@1.40.0 None 0 188 kB dougwilson
npm/mime-types@2.1.24 None 0 15.9 kB dougwilson
npm/mime@1.6.0 environment, filesystem 0 51.7 kB broofa
npm/mimic-fn@2.1.0 None 0 4.46 kB sindresorhus
npm/mimic-response@2.1.0 None 0 4.73 kB sindresorhus
npm/min-indent@1.0.0 None 0 3.01 kB thejameskyle
npm/mini-css-extract-plugin@0.9.0 unsafe 0 53.8 kB evilebottnawi
npm/minimalistic-assert@1.0.1 None 0 1.55 kB cwmma
npm/minimalistic-crypto-utils@1.0.1 None 0 4.76 kB indutny
npm/minimatch@3.0.4 None 0 33.1 kB isaacs
npm/minimist@1.2.5 None 0 32.4 kB substack
npm/minipass-collect@1.0.2 None 0 4.87 kB isaacs
npm/minipass-flush@1.0.5 None 0 3.77 kB isaacs
npm/minipass-pipeline@1.2.2 None 0 6.95 kB isaacs
npm/minipass@3.1.1 None 0 36.6 kB isaacs
npm/mississippi@3.0.0 None 0 16.3 kB bret
npm/mixin-deep@1.3.2 None 0 7.22 kB doowb
npm/mixin-object@2.0.1 None 0 5.81 kB jonschlinkert
npm/mkdirp@0.5.1 filesystem 0 21.2 kB substack
npm/mocha@6.1.4 environment, filesystem 0 983 kB boneskull
npm/move-concurrently@1.0.1 filesystem 0 7.95 kB iarna
npm/ms@2.1.1 None 0 6.82 kB leo
npm/multicast-dns-service-types@1.1.0 None 0 4.69 kB mafintosh
npm/multicast-dns@6.2.3 network 0 20.1 kB mafintosh
npm/multimatch@2.1.0 None 0 4.4 kB sindresorhus
npm/mute-stdout@1.0.1 None 0 3.96 kB phated
npm/mute-stream@0.0.7 None 0 75.6 kB isaacs
npm/nan@2.14.0 None 0 417 kB kkoopa
npm/nanomatch@1.2.13 None 0 86.3 kB jonschlinkert
npm/napi-build-utils@1.0.2 None 0 15.5 kB inspiredware
npm/natural-compare@1.4.0 None 0 5.65 kB megawac
npm/negotiator@0.6.2 None 0 28.1 kB dougwilson
npm/neo-async@2.6.1 None 0 297 kB suguru03
npm/next-tick@1.0.0 None 0 6.51 kB medikoo
npm/nice-try@1.0.5 None 0 3.75 kB electerious
npm/no-case@3.0.3 None 0 25 kB blakeembrey
npm/node-abi@2.15.0 None 0 19.7 kB lgeiger
npm/node-environment-flags@1.0.5 None 0 16 kB boneskull
npm/node-forge@0.9.0 None 0 1.69 MB davidlehn
npm/node-int64@0.4.0 None 0 16.3 kB broofa
npm/node-libs-browser@2.2.0 network, unsafe 0 10.5 kB sokra
npm/node-modules-regexp@1.0.0 None 0 2.73 kB jamestalmage
npm/node-notifier@6.0.0 environment, filesystem, network, shell 0 5.64 MB mikaelb
npm/node-releases@1.1.49 None 0 211 kB chicoxyzzy
npm/noop-logger@0.1.1 None 0 2.43 kB segment
npm/normalize-package-data@2.5.0 None 0 26.6 kB audrey.e
npm/normalize-path@2.1.1 None 0 8.46 kB jonschlinkert
npm/normalize-range@0.1.2 None 0 7.77 kB james.talmage
npm/normalize-url@1.9.1 None 0 9.27 kB sindresorhus
npm/now-and-later@2.0.1 None 0 14.6 kB phated
npm/npm-run-all@4.1.5 environment 0 92.5 kB mysticatea
npm/npm-run-path@2.0.2 environment 0 4.53 kB sindresorhus
npm/npmlog@4.1.2 None 0 17.4 kB iarna
npm/nth-check@1.0.2 None 0 5.54 kB feedic
npm/num2fraction@1.2.2 None 0 5.31 kB yisi
npm/number-is-nan@1.0.1 None 0 2.35 kB sindresorhus
npm/nwsapi@2.2.0 None 0 80.5 kB diego
npm/oauth-sign@0.9.0 None 0 13.8 kB simov
npm/object-assign@4.1.1 None 0 5.49 kB sindresorhus
npm/object-copy@0.1.0 None 0 5.47 kB jonschlinkert
npm/object-hash@2.0.3 None 0 58.7 kB addaleax
npm/object-inspect@1.7.0 None 0 30.6 kB ljharb
npm/object-is@1.0.2 None 0 16.5 kB ljharb
npm/object-keys@1.1.1 None 0 26.5 kB ljharb
npm/object-path@0.11.4 None 0 46 kB mariocasciaro
npm/object-visit@1.0.1 None 0 6.7 kB jonschlinkert
npm/object.assign@4.1.0 None 0 46.4 kB ljharb
npm/object.defaults@1.1.0 None 0 6.53 kB phated
npm/object.entries@1.1.0 None 0 21 kB ljharb
npm/object.fromentries@2.0.2 None 0 12 kB ljharb
npm/object.getownpropertydescriptors@2.0.3 None 0 26.8 kB ljharb
npm/object.map@1.0.1 None 0 6.34 kB phated
npm/object.pick@1.3.0 None 0 6.36 kB phated
npm/object.reduce@1.0.1 None 0 5.91 kB jonschlinkert
npm/object.values@1.1.1 None 0 13.4 kB ljharb
npm/obuf@1.1.2 None 0 19.1 kB indutny
npm/office-ui-fabric-react@7.105.12 environment 0 46.1 MB uifabricteam
npm/on-error-resume-next@1.1.0 None 0 9.59 kB compulim
npm/on-finished@2.3.0 None 0 12.3 kB dougwilson
npm/on-headers@1.0.2 None 0 7.54 kB dougwilson
npm/once@1.4.0 None 0 4.05 kB isaacs
npm/onetime@5.1.0 None 0 5.34 kB sindresorhus
npm/open@6.4.0 filesystem, shell 0 37 kB sindresorhus
npm/opn@5.5.0 shell 0 32 kB sindresorhus
npm/optimize-css-assets-webpack-plugin@5.0.3 None 0 17.4 kB nmfr
npm/optionator@0.8.2 None 0 49.5 kB gkz
npm/ordered-read-streams@1.0.1 None 0 5.08 kB phated
npm/original@1.0.2 None 0 4.8 kB 3rdeden
npm/os-browserify@0.3.0 None 0 2.74 kB coderpuppy
npm/os-homedir@1.0.2 environment 0 3.15 kB sindresorhus
npm/os-locale@3.1.0 environment 0 6.18 kB sindresorhus
npm/os-tmpdir@1.0.2 None 0 3.06 kB sindresorhus
npm/os@0.1.1 None 0 2.77 kB diegorbaquero
npm/osenv@0.1.5 environment, shell 0 4.89 kB isaacs
npm/p-defer@1.0.0 None 0 2.94 kB sindresorhus
npm/p-each-series@2.1.0 None 0 5.53 kB sindresorhus

View full report↗︎

Copy link

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSource
Known Malware npm/fsevents@1.2.9
  • Note: This package downloads prebuilt artifacts from a domain which has been compromised. Your system may be infected if you installed this package prior to April 27, 2023
Install scripts npm/fsevents@1.2.9
  • Install script: install
  • Source: node install
Protestware/Troll package npm/es5-ext@0.10.50
  • Note: This package prints a protestware console message on install regarding Ukraine for users with Russian language locale

View full report↗︎

Next steps

What is known malware?

This package is malware. We have asked the package registry to remove it.

It is strongly recommended that malware is removed from your codebase.

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

What is protestware?

This package is a joke, parody, or includes undocumented or hidden behavior unrelated to its primary function.

Consider that consuming this package my come along with functionality unrelated to its primary purpose.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/fsevents@1.2.9
  • @SocketSecurity ignore npm/es5-ext@0.10.50

Copy link
Author

dependabot bot commented on behalf of github Apr 5, 2024

Dependabot couldn't find any dependency files in the directory. Because of this, Dependabot cannot update this pull request.

2 similar comments
Copy link
Author

dependabot bot commented on behalf of github Apr 11, 2024

Dependabot couldn't find any dependency files in the directory. Because of this, Dependabot cannot update this pull request.

Copy link
Author

dependabot bot commented on behalf of github Apr 13, 2024

Dependabot couldn't find any dependency files in the directory. Because of this, Dependabot cannot update this pull request.

NikolaRHristov and others added 6 commits April 15, 2024 02:35
Bumps [black](https://github.com/psf/black) from 19.10b0 to 24.3.0.
- [Release notes](https://github.com/psf/black/releases)
- [Changelog](https://github.com/psf/black/blob/main/CHANGES.md)
- [Commits](https://github.com/psf/black/commits/24.3.0)

---
updated-dependencies:
- dependency-name: black
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pillow](https://github.com/python-pillow/Pillow) from 8.1.1 to 10.3.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@8.1.1...10.3.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Copy link
Author

dependabot bot commented on behalf of github Apr 15, 2024

Dependabot couldn't find any dependency files in the directory. Because of this, Dependabot cannot update this pull request.

NikolaRHristov and others added 4 commits April 20, 2024 04:57
Bumps [pillow](https://github.com/python-pillow/Pillow) from 8.1.1 to 10.3.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@8.1.1...10.3.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/pip/src/pillow-10.3.0 branch from c087bfc to 805e0be Compare April 23, 2024 13:28
Copy link
Author

dependabot bot commented on behalf of github Apr 29, 2024

Dependabot couldn't find any dependency files in the directory. Because of this, Dependabot cannot update this pull request.

Copy link
Author

dependabot bot commented on behalf of github May 1, 2024

Dependabot couldn't find any dependency files in the directory. Because of this, Dependabot cannot update this pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file python Pull requests that update Python code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant