Skip to content

Prepare Release#604

Merged
CoveMB merged 5 commits intomasterfrom
changeset-release/master
Jul 22, 2025
Merged

Prepare Release#604
CoveMB merged 5 commits intomasterfrom
changeset-release/master

Conversation

@github-actions
Copy link
Contributor

@github-actions github-actions bot commented Jul 22, 2025

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to master, this PR will be updated.

Releases

@openzeppelin/wizard-stellar@0.4.1

Changelog

0.4.1 (2025-07-22)

  • Dependencies from crates.io and remove unused imports (#602)
    • Breaking changes:
      • Use OpenZeppelin Stellar Soroban Contracts v0.4.1

@socket-security
Copy link

socket-security bot commented Jul 22, 2025

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert (click for details)
Block High
@eslint/plugin-kit@0.2.7 has a High CVE.

CVE: GHSA-xffm-g5w8-qvg7 @eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser (HIGH)

Affected versions: < 0.3.3

Patched version: 0.3.3

From: yarn.locknpm/@eslint/plugin-kit@0.2.7

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@eslint/plugin-kit@0.2.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@CoveMB
Copy link
Contributor

CoveMB commented Jul 22, 2025

Security alert are not related to those changes

@CoveMB CoveMB enabled auto-merge (squash) July 22, 2025 20:40
@CoveMB CoveMB merged commit a8c839b into master Jul 22, 2025
20 of 22 checks passed
@CoveMB CoveMB deleted the changeset-release/master branch July 22, 2025 20:40
@github-actions github-actions bot locked and limited conversation to collaborators Jul 22, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants