Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: Support Blast constants #550

Merged
merged 2 commits into from
Jul 9, 2024
Merged

feat: Support Blast constants #550

merged 2 commits into from
Jul 9, 2024

Conversation

pxrl
Copy link
Contributor

@pxrl pxrl commented Jul 9, 2024

No description provided.

@pxrl pxrl requested review from dohaki and bmzig July 9, 2024 16:09
@pxrl
Copy link
Contributor Author

pxrl commented Jul 9, 2024

nb. This needs a sync of yarn.lock + yarn lint. Done

Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@across-protocol/[email protected] None 0 79.5 kB mrice32
npm/@eth-optimism/[email protected] None +1 211 kB karlfloersch
npm/@ethersproject/[email protected] None 0 30.1 kB ricmoo
npm/@ethersproject/[email protected] None 0 250 kB ricmoo
npm/@ethersproject/[email protected] network 0 1.2 MB ricmoo
npm/@ethersproject/[email protected] None 0 17.3 kB ricmoo
npm/@ethersproject/[email protected] None 0 21.7 kB ricmoo
npm/@nomicfoundation/[email protected] environment, eval Transitive: filesystem, network +9 2.78 MB fvictorio
npm/@nomicfoundation/[email protected] None +5 363 kB fvictorio
npm/@nomiclabs/[email protected] None 0 39.6 kB alcuadrado
npm/@openzeppelin/[email protected] filesystem Transitive: environment +3 484 kB ericglau
npm/@openzeppelin/[email protected] environment, filesystem 0 3.87 MB ericglau
npm/@pinata/[email protected] Transitive: environment, network +1 4.31 MB polluterofminds
npm/@protobufjs/[email protected] None 0 9.05 kB dcode
npm/@typechain/[email protected] filesystem 0 87.7 kB ethereum-ts-bot
npm/@typechain/[email protected] filesystem 0 29.3 kB ethereum-ts-bot
npm/@types/[email protected] None 0 13.9 kB types
npm/@types/[email protected] None 0 77.2 kB types
npm/@types/[email protected] None 0 96.1 kB types
npm/@types/[email protected] None 0 758 kB types
npm/@typescript-eslint/[email protected] None 0 2.36 MB jameshenry
npm/@typescript-eslint/[email protected] None 0 71.5 kB jameshenry
npm/[email protected] None 0 484 kB vweevers
npm/[email protected] None 0 9.37 kB sindresorhus
npm/[email protected] None +1 25.7 MB fredlacs
npm/[email protected] None +2 24.2 MB fredlacs
npm/[email protected] environment 0 11.4 kB pfmooney
npm/[email protected] None 0 19.2 kB ahultgren
npm/[email protected] None 0 9.62 kB feross
npm/[email protected] None 0 154 kB hildjj
npm/[email protected] None 0 752 kB chai
npm/[email protected] None +3 63.5 kB sindresorhus
npm/[email protected] environment, filesystem 0 90.1 kB paulmillr
npm/[email protected] None 0 15.9 kB pvorb
npm/[email protected] environment 0 42.4 kB qix
npm/[email protected] environment, filesystem 0 24.9 kB motdotla
npm/[email protected] environment 0 197 kB jonschlinkert
npm/[email protected] None 0 18.1 kB lydell
npm/[email protected] None 0 16.4 kB linusu
npm/[email protected] filesystem, unsafe 0 1.04 MB ljharb
npm/[email protected] filesystem 0 269 kB mysticatea
npm/[email protected] filesystem 0 52.5 kB bpscott
npm/[email protected] None 0 42.5 kB xjamundx
npm/[email protected] filesystem +8 3.35 MB eslintbot
npm/[email protected] None 0 36.3 kB michaelficarra
npm/[email protected] None +1 807 kB paulmillr
npm/[email protected] None 0 20.3 kB ethworks
npm/[email protected] None 0 68.4 kB holgerd77
npm/[email protected] None +5 492 kB holgerd77
npm/[email protected] None 0 10.7 MB ricmoo
npm/[email protected] None 0 23.5 kB ljharb
npm/[email protected] None 0 22.8 kB dap
npm/[email protected] None 0 4.8 kB sindresorhus
npm/[email protected] None 0 59.5 kB ryanzim
npm/[email protected] None 0 156 kB pipobscure
npm/[email protected] None 0 43.5 kB mikolalysenko
npm/[email protected] filesystem Transitive: environment +1 68.2 kB isaacs
npm/[email protected] environment, filesystem 0 31.6 kB isaacs
npm/[email protected] environment, filesystem +1 12.4 MB wighawag
npm/[email protected] filesystem 0 73.1 kB cgewecke
npm/[email protected] environment, filesystem, network, shell Transitive: eval +56 26 MB fvictorio
npm/[email protected] environment, filesystem, shell +2 69.9 kB typicode
npm/[email protected] None 0 6.8 kB feross
npm/[email protected] None 0 6.93 kB doowb
npm/[email protected] None 0 779 kB fanatid
npm/[email protected] None +1 30.4 kB isaacs
npm/[email protected] None 0 3.58 kB sindresorhus
npm/[email protected] environment, eval, filesystem +7 2.16 MB juergba
npm/[email protected] None 0 529 kB npm-service-account-multiformats
npm/[email protected] None 0 696 kB janther
npm/[email protected] environment, eval, filesystem, unsafe 0 21 MB sosukesuzuki
npm/[email protected] filesystem Transitive: environment +2 87.4 kB azz
npm/[email protected] None 0 29.9 kB hugomrdias
npm/[email protected] network, unsafe +1 361 kB dougwilson
npm/[email protected] environment 0 122 kB matteo.collina
npm/[email protected] None 0 9.09 kB jonschlinkert
npm/[email protected] None +1 2.69 MB fanatid
npm/[email protected] None 0 88.2 kB isaacs
npm/[email protected] filesystem Transitive: environment +1 233 kB fvictorio
npm/[email protected] filesystem Transitive: environment +2 171 kB cgewecke
npm/[email protected] None +1 340 kB gajus-table
npm/[email protected] filesystem 0 27.7 kB mafintosh
npm/[email protected] environment, filesystem, unsafe 0 591 kB cspotcode
npm/[email protected] filesystem Transitive: environment +2 134 kB ethereum-ts-bot
npm/[email protected] None 0 64.7 MB typescript-bot
npm/[email protected] environment, network, unsafe 0 1.08 MB matteo.collina
npm/[email protected] filesystem, network 0 268 kB dabh
npm/[email protected] network 0 113 kB lpinca
npm/[email protected] None 0 6.46 kB raynos
npm/[email protected] environment 0 448 kB eemeli

🚮 Removed packages: npm/@across-protocol/[email protected], npm/@babel/[email protected], npm/@babel/[email protected], npm/@babel/[email protected], npm/@babel/[email protected], npm/@babel/[email protected], npm/@jridgewell/[email protected], npm/@jridgewell/[email protected], npm/@noble/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected]

View full report↗︎

Copy link

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSourceCI
Install scripts npm/[email protected]
  • Install script: install
  • Source: node husky install
🚫
Install scripts npm/[email protected]
  • Install script: postinstall
  • Source: opencollective-postinstall || exit 0
🚫
Install scripts npm/[email protected]
  • Install script: postinstall
  • Source: $npm_execpath run clean:build
🚫
Install scripts npm/[email protected]
  • Install script: postinstall
  • Source: $npm_execpath run clean:build
🚫

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/[email protected] or ignore all packages with @SocketSecurity ignore-all

Signed-off-by: bennett <[email protected]>
@pxrl pxrl merged commit 8febef3 into master Jul 9, 2024
11 checks passed
@pxrl pxrl deleted the pxrl/blastConstants branch July 9, 2024 16:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants