Skip to content

chore(deps): update jamesives/github-pages-deploy-action action to v4.7.4#3

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/jamesives-github-pages-deploy-action-4.x
Open

chore(deps): update jamesives/github-pages-deploy-action action to v4.7.4#3
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/jamesives-github-pages-deploy-action-4.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Mar 28, 2022

This PR contains the following updates:

Package Type Update Change
JamesIves/github-pages-deploy-action action minor 4.1.9 -> v4.7.4

Release Notes

JamesIves/github-pages-deploy-action (JamesIves/github-pages-deploy-action)

v4.7.4

Compare Source

What's Changed

Bug Fixes 🐛
Build 🔧
Other Changes
  • Add comprehensive GitHub Copilot instructions for development workflow by @​Copilot in #​1894

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.7.4

v4.7.3

Compare Source

What's Changed
Build 🔧
Other Changes

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.7.3

v4.7.2

Compare Source

What's Changed
Bug Fixes 🐝
  • fix: enable rsync mkpath to be backwards compatible with older Ubuntu versions by @​JamesIves in #​1757
Build 🔧

Full Changelog: JamesIves/github-pages-deploy-action@v4.7.1...v4.7.2

v4.7.1

Compare Source

What's Changed
Features ✨
  • feat: when target-folder is specified the action will now create any missing folders for you by @​databasedav in #​1737
New Contributors

Full Changelog: JamesIves/github-pages-deploy-action@v4.6.6...v4.7.1

v4.7.0

Compare Source

What's Changed
Features ✨
  • feat: added the option to specify an atttempt-limit input, giving you the option to change how many attempts the action will make before failing by @​databasedav in #​1737
Build 🔧
New Contributors

Full Changelog: JamesIves/github-pages-deploy-action@v4.6.6...v4.7.0

v4.6.9

Compare Source

What's Changed
Dependencies 🤖
  • chore(deps): mass bump dependencies
  • chore(deps): switch to using .node-version instead of .nvmrc for Node dependency management.
  • chore(deps): updated node version to 22.11.0 for development

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.6.9

v4.6.8

Compare Source

What's Changed
Bug Fixes 🐝
  • fix: 🐛 Added the temp deployment directory created by the action to the git safe directory list. This resolves an issue in certain circumstances where the deployment would fail depending on the types of files moved around by the workflow - #​1694.
  • fix: Resolved a rare deployment error where the action would complain that origin/${branch_name} is not a commit and a branch cannot be created from it. The action will continue to attempt to track the origin branch, but if this step fails, it will create a new untracked branch to continue the deployment from. - #​1689.
Testing 🧪
  • test: 🧪 Improved the integration test suite so it now runs immediately post-release to ensure that any issues do no longer in the major version tag (ie @​v4). This was done to combat problems raised by #​1697.

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.6.8

v4.6.7

Compare Source

What's Changed
Bug Fixes 🐝
  • fix: resolved an issue where main.js was not found in the v4 major tag.

v4.6.6

Compare Source

What's Changed
Bug Fixes 🐝
  • revert: reverts a prior change that unsets safe directories to prevent dubious ownership, this change will be re-visited later.

v4.6.5

Compare Source

What's Changed
What's Changed
Bug Fixes 🐝
  • fix: resolved an issue where the full working directory was not properly getting added to the safe directory list, preventing deployments in certain circumstances.

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.6.5

v4.6.4

Compare Source

What's Changed
What's Changed
Bug Fixes 🐝
  • fix: resolved an issue where the default config was not being applied to the non-action version of the project.
Build 🔧

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.6.4

v4.6.3

Compare Source

What's Changed
Build 🔧
  • Consolidated a number of build scripts to make publishing easier.

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.6.3

v4.6.2

Compare Source

What's Changed
Dependencies 🤖

Full Changelog: JamesIves/github-pages-deploy-action@v4.6.1...v4.6.2

v4.6.1

Compare Source

What's Changed
Fixes
  • Resolved an issue where workflows were suddenly failing due to a worktree in use error. The action will now attempt to create a temp branch name if the existing branch name is already checked out by a prior to step to ensure it can occur. This issue was only occurring in a handful of workflows, and likely stemmed from a git version change on the official GitHub runners. The actual root cause is still somewhat unknown.
Dependencies

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.6.1

v4.6.0

Compare Source

What's Changed
New Contributors

Full Changelog: JamesIves/github-pages-deploy-action@v4.5.0...v4.6.0

v4.5.0

Compare Source

What's Changed
New Contributors

Full Changelog: JamesIves/github-pages-deploy-action@v4.4.3...v4.5.0

v4.4.3

Compare Source

What's Changed

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.4.3

v4.4.2

Compare Source

What's Changed
  • Dependency updates

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.4.2

v4.4.1

Compare Source

What's Changed

Changelog

New Contributors

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.4.1

v4.4.0

Compare Source

What's Changed

  • Adding tag option to action by @​germa89 in #​1142 - this can be used by applying a version number to your workflow. You can source this input via a workflow variable to dynamically add a tag to a branch on each deployment. You can find more information about how to use this field in the readme.
  • fix: 🐛 Fixes an issue where informational messages are throwing errors by in #​1168
  • Bump eslint-plugin-prettier from 4.0.0 to 4.2.1 by @​dependabot in #​1159
  • Bump @​types/node from 18.0.0 to 18.0.6 by @​dependabot in #​1169

New Contributors

Sponsors ❤️

github  

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.4.0

v4.3.4

Compare Source

Minor Changes

  • The branch parameter is no longer required. It now defaults to gh-pages.
  • Linting scripts have been updated to ensure that everything across the repo gets picked up.
  • Numerous dependency updates.

New Contributors

Sponsors ❤️

github  

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.3.4

v4.3.3

[Compare Source]


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, on day 1 of the month ( * 0-3 1 * * ) in timezone Europe/Paris, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.2.5 chore(deps): update jamesives/github-pages-deploy-action action to v4.3.0 Apr 4, 2022
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 1f43fa5 to 7d56702 Compare April 4, 2022 15:32
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 7d56702 to 67c732f Compare April 23, 2022 20:24
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.3.0 chore(deps): update jamesives/github-pages-deploy-action action to v4.3.1 Apr 23, 2022
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.3.1 chore(deps): update jamesives/github-pages-deploy-action action to v4.3.2 Apr 23, 2022
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 67c732f to a83f250 Compare April 23, 2022 22:44
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.3.2 chore(deps): update jamesives/github-pages-deploy-action action to v4.3.3 Apr 26, 2022
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from a83f250 to b762ee7 Compare April 26, 2022 04:30
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.3.3 chore(deps): update jamesives/github-pages-deploy-action action to v4.3.3 - autoclosed Jun 4, 2022
@renovate renovate Bot closed this Jun 4, 2022
@renovate renovate Bot deleted the renovate/jamesives-github-pages-deploy-action-4.x branch June 4, 2022 04:12
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.3.3 - autoclosed chore(deps): update jamesives/github-pages-deploy-action action to v4.3.3 Jun 4, 2022
@renovate renovate Bot restored the renovate/jamesives-github-pages-deploy-action-4.x branch June 4, 2022 10:00
@renovate renovate Bot reopened this Jun 4, 2022
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from b762ee7 to d6e211a Compare June 26, 2022 16:02
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.3.3 chore(deps): update jamesives/github-pages-deploy-action action to v4.3.4 Jun 26, 2022
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.3.4 chore(deps): update JamesIves/github-pages-deploy-action action to v4.3.4 Jun 27, 2022
@renovate renovate Bot changed the title chore(deps): update JamesIves/github-pages-deploy-action action to v4.3.4 chore(deps): update jamesives/github-pages-deploy-action action to v4.3.4 Jun 28, 2022
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from d6e211a to 9b57a78 Compare September 25, 2022 16:05
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.3.4 chore(deps): update jamesives/github-pages-deploy-action action to v4.4.0 Sep 25, 2022
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 9b57a78 to 58051d4 Compare October 19, 2022 14:55
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.4.0 chore(deps): update jamesives/github-pages-deploy-action action to v4.4.1 Oct 19, 2022
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.4.1 chore(deps): update jamesives/github-pages-deploy-action action to v4.4.2 May 29, 2023
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 58051d4 to 7fea3a7 Compare May 29, 2023 17:51
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.4.2 chore(deps): update jamesives/github-pages-deploy-action action to v4.4.3 Jul 12, 2023
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 7fea3a7 to 2340e59 Compare July 12, 2023 02:38
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 2340e59 to 6b111cc Compare November 28, 2023 05:53
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.4.3 chore(deps): update jamesives/github-pages-deploy-action action to v4.5.0 Nov 28, 2023
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 6b111cc to fdc09fa Compare December 12, 2023 02:14
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.5.0 chore(deps): update jamesives/github-pages-deploy-action action to v4.6.0 Apr 17, 2024
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from fdc09fa to d03a119 Compare April 17, 2024 14:14
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from d03a119 to 8625912 Compare May 18, 2024 13:46
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.6.0 chore(deps): update jamesives/github-pages-deploy-action action to v4.6.1 May 18, 2024
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 8625912 to 2c08c4c Compare July 5, 2024 19:05
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.6.1 chore(deps): update jamesives/github-pages-deploy-action action to v4.6.3 Jul 5, 2024
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 2c08c4c to dc020d2 Compare September 2, 2024 17:05
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.6.3 chore(deps): update jamesives/github-pages-deploy-action action to v4.6.4 Sep 2, 2024
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from dc020d2 to e3da3d5 Compare September 27, 2024 15:46
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.6.4 chore(deps): update jamesives/github-pages-deploy-action action to v4.6.5 Sep 27, 2024
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from e3da3d5 to ac707ae Compare September 27, 2024 18:57
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.6.5 chore(deps): update jamesives/github-pages-deploy-action action to v4.6.6 Sep 27, 2024
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from ac707ae to 340fa66 Compare September 28, 2024 13:35
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.6.6 chore(deps): update jamesives/github-pages-deploy-action action to v4.6.7 Sep 28, 2024
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 340fa66 to 543f4ea Compare September 29, 2024 16:52
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.6.7 chore(deps): update jamesives/github-pages-deploy-action action to v4.6.8 Sep 29, 2024
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 543f4ea to 66572b1 Compare November 9, 2024 22:45
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.6.8 chore(deps): update jamesives/github-pages-deploy-action action to v4.6.9 Nov 9, 2024
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.6.9 chore(deps): update jamesives/github-pages-deploy-action action to v4.7.0 Nov 28, 2024
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch 2 times, most recently from b3b257e to ff4db9a Compare November 28, 2024 15:36
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.7.0 chore(deps): update jamesives/github-pages-deploy-action action to v4.7.1 Nov 28, 2024
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from ff4db9a to 3426a8d Compare December 3, 2024 19:29
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.7.1 chore(deps): update jamesives/github-pages-deploy-action action to v4.7.2 Dec 3, 2024
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.7.2 chore(deps): update jamesives/github-pages-deploy-action action to v4.7.3 Feb 19, 2025
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 3426a8d to 939d2dc Compare February 19, 2025 17:44
@renovate renovate Bot force-pushed the renovate/jamesives-github-pages-deploy-action-4.x branch from 939d2dc to f89c76c Compare November 4, 2025 19:06
@renovate renovate Bot changed the title chore(deps): update jamesives/github-pages-deploy-action action to v4.7.3 chore(deps): update jamesives/github-pages-deploy-action action to v4.7.4 Nov 4, 2025
@socket-security
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: npm cipher-base is missing type checks, leading to hash rewind and passing on crafted data

CVE: GHSA-cpq7-6gpm-g9rc cipher-base is missing type checks, leading to hash rewind and passing on crafted data (CRITICAL)

Affected versions: < 1.0.5

Patched version: 1.0.5

From: ?npm/cipher-base@1.0.4

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/cipher-base@1.0.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: npm ejs template injection vulnerability

CVE: GHSA-phwq-j96m-2c2q ejs template injection vulnerability (CRITICAL)

Affected versions: < 3.1.7

Patched version: 3.1.7

From: ?npm/ejs@2.7.4

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ejs@2.7.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)

CVE: GHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string) (CRITICAL)

Affected versions: < 6.6.1

Patched version: 6.6.1

From: ?npm/elliptic@6.5.4

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/elliptic@6.5.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Exposure of Sensitive Information in npm eventsource

CVE: GHSA-6h5x-7c5m-7cr7 Exposure of Sensitive Information in eventsource (CRITICAL)

Affected versions: < 1.1.1; >= 2.0.0 < 2.0.2

Patched version: 1.1.1

From: ?npm/eventsource@1.1.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/eventsource@1.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: npm form-data uses unsafe random function in form-data for choosing boundary

CVE: GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundary (CRITICAL)

Affected versions: < 2.5.4; >= 3.0.0 < 3.0.4; >= 4.0.0 < 4.0.4

Patched version: 3.0.4

From: ?npm/form-data@3.0.1

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/form-data@3.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm buffer is 96.0% likely obfuscated

Confidence: 0.96

Location: Package overview

From: ?npm/buffer@4.9.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/buffer@4.9.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Protestware or unwanted behavior: npm es5-ext

Note: This package prints a protestware console message on install regarding Ukraine for users with Russian language locale

From: ?npm/es5-ext@0.10.58

ℹ Read more on: This package | This alert | What is protestware?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Consider that consuming this package may come along with functionality unrelated to its primary purpose.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es5-ext@0.10.58. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Protestware or unwanted behavior: npm es5-ext

Note: The script attempts to run a local '_postinstall' script, but it does so in a way that suppresses errors. This could potentially hide malicious behavior if '_postinstall' contains harmful code.

From: ?npm/es5-ext@0.10.58

ℹ Read more on: This package | This alert | What is protestware?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Consider that consuming this package may come along with functionality unrelated to its primary purpose.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es5-ext@0.10.58. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants