Skip to content

Comments

chore: audit packages#214

Merged
arobsn merged 3 commits intomasterfrom
audit-deps
Feb 8, 2026
Merged

chore: audit packages#214
arobsn merged 3 commits intomasterfrom
audit-deps

Conversation

@arobsn
Copy link
Member

@arobsn arobsn commented Feb 8, 2026

No description provided.

@changeset-bot
Copy link

changeset-bot bot commented Feb 8, 2026

🦋 Changeset detected

Latest commit: 15d7794

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
Name Type
@fleet-sdk/mock-chain Patch
@fleet-sdk/blockchain-providers Patch
@fleet-sdk/common Patch
@fleet-sdk/compiler Patch
@fleet-sdk/core Patch
@fleet-sdk/crypto Patch
@fleet-sdk/serializer Patch
@fleet-sdk/wallet Patch
@fleet-sdk/ageusd-plugin Patch
@fleet-sdk/babel-fees-plugin Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@socket-security
Copy link

socket-security bot commented Feb 8, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​vitest/​coverage-v8@​4.0.10 ⏵ 4.0.1899 +11006999100
Updatedvitest@​4.0.10 ⏵ 4.0.1896 -110079 +199100
Updated@​changesets/​cli@​2.29.7 ⏵ 2.29.89610010089100
Updatedfast-check@​4.3.0 ⏵ 4.5.310010010090 -2100
Updatedtsdown@​0.16.5 ⏵ 0.16.89810092 +196 +1100
Updateddiff@​8.0.2 ⏵ 8.0.399 +1100 +1100 +193100
Updatedhappy-dom@​20.0.10 ⏵ 20.5.2100 +6100100 +13100 +7100

View full report

@socket-security
Copy link

socket-security bot commented Feb 8, 2026

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: pnpm-lock.yamlnpm/happy-dom@20.5.2npm/entities@6.0.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@6.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@codecov
Copy link

codecov bot commented Feb 8, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (d665d3c) to head (15d7794).
⚠️ Report is 6 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff            @@
##            master      #214   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files           99        99           
  Lines         3307      3307           
  Branches       806       806           
=========================================
  Hits          3307      3307           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pkg-pr-new
Copy link

pkg-pr-new bot commented Feb 8, 2026

@fleet-sdk/blockchain-providers

npm i https://pkg.pr.new/@fleet-sdk/blockchain-providers@214

@fleet-sdk/common

npm i https://pkg.pr.new/@fleet-sdk/common@214

@fleet-sdk/compiler

npm i https://pkg.pr.new/@fleet-sdk/compiler@214

@fleet-sdk/core

npm i https://pkg.pr.new/@fleet-sdk/core@214

@fleet-sdk/crypto

npm i https://pkg.pr.new/@fleet-sdk/crypto@214

@fleet-sdk/mock-chain

npm i https://pkg.pr.new/@fleet-sdk/mock-chain@214

@fleet-sdk/serializer

npm i https://pkg.pr.new/@fleet-sdk/serializer@214

@fleet-sdk/wallet

npm i https://pkg.pr.new/@fleet-sdk/wallet@214

@fleet-sdk/ageusd-plugin

npm i https://pkg.pr.new/@fleet-sdk/ageusd-plugin@214

@fleet-sdk/babel-fees-plugin

npm i https://pkg.pr.new/@fleet-sdk/babel-fees-plugin@214

commit: 15d7794

@arobsn arobsn merged commit 300de64 into master Feb 8, 2026
16 checks passed
@arobsn arobsn deleted the audit-deps branch February 8, 2026 23:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant