Skip to content

Feat/add socket scan#3

Open
arbarg2 wants to merge 5 commits into
mainfrom
feat/add-socket-scan
Open

Feat/add socket scan#3
arbarg2 wants to merge 5 commits into
mainfrom
feat/add-socket-scan

Conversation

@arbarg2
Copy link
Copy Markdown
Owner

@arbarg2 arbarg2 commented May 23, 2026

No description provided.

@vercel
Copy link
Copy Markdown

vercel Bot commented May 23, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
pmtest Ready Ready Preview, Comment May 23, 2026 2:15pm

@socket-security
Copy link
Copy Markdown

socket-security Bot commented May 23, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​scarf/​scarf@​1.4.08210010080100

View full report

@vercel vercel Bot requested a deployment to Preview May 23, 2026 14:10 Abandoned
@vercel
Copy link
Copy Markdown

vercel Bot commented May 23, 2026

Deployment failed with the following error:

The provided GitHub repository does not contain the requested branch or commit reference. Please ensure the repository is not empty.

@github-actions
Copy link
Copy Markdown

Socket Security: Dependency Overview

Review the following changes in direct dependencies. Learn more about socket.dev

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
+ xlsx@0.18.5 90 78 100 80 100
+ tailwindcss-animate@1.0.7 100 100 99 79 100
+ cmdk@1.0.0 99 100 99 81 100
+ next-themes@0.3.0 100 100 62 81 100
+ date-fns@3.6.0 83 100 92 90 100
+ input-otp@1.2.4 100 100 99 80 100
+ react-day-picker@8.10.1 98 100 92 95 100
+ clsx@2.1.1 100 100 94 79 100
+ react-dom@18.3.1 92 100 91 96 100
+ react@18.3.1 99 100 84 96 100
+ zod@3.23.8 97 100 100 95 100
+ sonner@1.5.0 99 100 79 82 100
+ @radix-ui/react-slot@1.1.0 100 100 71 89 100
+ @radix-ui/react-separator@1.1.0 99 100 70 89 100
+ @radix-ui/react-toggle@1.1.0 99 100 70 90 100
+ @radix-ui/react-toggle-group@1.1.0 99 100 73 90 100
+ @radix-ui/react-progress@1.1.0 99 100 72 89 100
+ @radix-ui/react-label@2.1.0 99 100 69 89 100
+ eslint-plugin-react-hooks@5.1.0-rc-fb9a90fa48-20240614 98 100 93 95 100
+ @radix-ui/react-aspect-ratio@1.1.0 99 100 70 89 100
+ @hookform/resolvers@3.9.0 99 100 99 86 100
+ autoprefixer@10.4.20 99 100 91 85 100
+ embla-carousel-react@8.3.0 99 100 99 85 100
+ postcss@8.4.47 99 99 82 93 100
+ vaul@0.9.9 98 100 100 80 100
+ @vitejs/plugin-react-swc@3.7.1 99 100 100 89 100
+ @radix-ui/react-dialog@1.1.2 98 100 74 90 100
+ @radix-ui/react-menubar@1.1.2 99 100 75 91 100
+ @radix-ui/react-switch@1.1.1 99 100 72 90 100
+ @radix-ui/react-tabs@1.1.1 99 100 73 90 100
+ @radix-ui/react-toast@1.2.2 99 100 75 90 100
+ @radix-ui/react-scroll-area@1.2.0 99 100 75 90 100
+ @radix-ui/react-accordion@1.2.1 99 100 74 90 100
+ @radix-ui/react-collapsible@1.1.1 99 100 72 90 100
+ @radix-ui/react-dropdown-menu@2.1.2 99 100 74 90 100
+ @radix-ui/react-popover@1.1.2 98 100 74 90 100
+ @radix-ui/react-slider@1.2.1 99 100 75 90 100
+ @radix-ui/react-checkbox@1.1.2 99 100 73 90 100
+ @radix-ui/react-select@2.1.2 98 100 76 90 100
+ @radix-ui/react-alert-dialog@1.1.2 99 100 75 90 100
+ @radix-ui/react-avatar@1.1.1 99 100 72 89 100
+ @radix-ui/react-context-menu@2.2.2 99 100 74 90 100
+ @radix-ui/react-hover-card@1.1.2 99 100 74 90 100
+ @radix-ui/react-navigation-menu@1.2.1 98 100 75 90 100
+ @radix-ui/react-radio-group@1.2.1 99 100 74 90 100
+ typescript@5.6.3 99 100 89 96 90
+ globals@15.11.0 100 100 85 93 100
+ recharts@2.13.0 74 100 100 91 100
+ react-router-dom@6.27.0 96 100 74 96 100
+ tailwind-merge@2.5.4 99 100 85 95 100
+ @eslint/js@9.13.0 100 100 86 88 100
+ eslint@9.13.0 88 100 100 96 100
+ react-hook-form@7.53.1 97 100 100 94 100
+ typescript-eslint@8.11.0 100 100 75 97 100
+ vite@5.4.10 91 75 82 97 100
+ @types/node@22.7.9 100 100 81 96 100
+ @types/react@18.3.12 100 100 79 95 100
+ @tanstack/react-query@5.59.16 99 100 88 99 100
+ react-resizable-panels@2.1.5 99 100 100 95 100
+ eslint-plugin-react-refresh@0.4.14 100 100 99 85 100
+ @scarf/scarf@1.4.0 82 100 100 80 100
+ @radix-ui/react-tooltip@1.1.4 99 100 75 90 100
+ class-variance-authority@0.7.1 99 100 67 80 100
+ lucide-react@0.462.0 100 100 93 95 100
+ tailwindcss@3.4.17 95 100 86 98 100
+ @tailwindcss/typography@0.5.16 99 100 99 91 100
+ remark-gfm@4.0.1 99 100 99 82 100
+ lovable-tagger@1.1.7 99 100 73 88 100
+ react-markdown@10.1.0 98 100 100 83 100
+ jspdf@3.0.1 97 25 99 83 100
+ @types/papaparse@5.3.16 100 100 74 82 100
+ papaparse@5.5.3 99 100 94 81 100
+ @supabase/supabase-js@2.50.5 99 100 100 100 100

@github-actions
Copy link
Copy Markdown

❗️ Caution
Review the following alerts detected in dependencies.

According to your organization's policies, you must resolve all "Block" alerts before proceeding. It's recommended to resolve "Warn" alerts too.
Learn more about Socket for GitHub.

Action Severity Alert (click for details)
Warn SocketIssueSeverity.HIGH
codepage@1.15.0 - Obfuscated code

Note: Obfuscated files are intentionally packed to hide their behavior. This could be a sign of malware

Source: Manifest File

ℹ️ Read more on: This package | This alert | What is known malware?

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code

Mark as acceptable risk: To ignore this alert only in this pull request, reply with:
@SocketSecurity ignore codepage@1.15.0
Or ignore all future alerts with:
@SocketSecurity ignore-all

Warn SocketIssueSeverity.HIGH
date-fns@3.6.0 - Obfuscated code

Note: Obfuscated files are intentionally packed to hide their behavior. This could be a sign of malware

Source: Manifest File

ℹ️ Read more on: This package | This alert | What is known malware?

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code

Mark as acceptable risk: To ignore this alert only in this pull request, reply with:
@SocketSecurity ignore date-fns@3.6.0
Or ignore all future alerts with:
@SocketSecurity ignore-all

Warn SocketIssueSeverity.HIGH
recharts@2.13.0 - Obfuscated code

Note: Obfuscated files are intentionally packed to hide their behavior. This could be a sign of malware

Source: Manifest File

ℹ️ Read more on: This package | This alert | What is known malware?

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code

Mark as acceptable risk: To ignore this alert only in this pull request, reply with:
@SocketSecurity ignore recharts@2.13.0
Or ignore all future alerts with:
@SocketSecurity ignore-all

Warn SocketIssueSeverity.HIGH
caniuse-lite@1.0.30001669 - Obfuscated code

Note: Obfuscated files are intentionally packed to hide their behavior. This could be a sign of malware

Source: Manifest File

ℹ️ Read more on: This package | This alert | What is known malware?

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code

Mark as acceptable risk: To ignore this alert only in this pull request, reply with:
@SocketSecurity ignore caniuse-lite@1.0.30001669
Or ignore all future alerts with:
@SocketSecurity ignore-all

Warn SocketIssueSeverity.CRITICAL
jspdf@3.0.1 - Critical CVE

Note: Contains a Critical Common Vulnerability and Exposure (CVE).

Source: Manifest File

ℹ️ Read more on: This package | This alert | What is known malware?

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark as acceptable risk: To ignore this alert only in this pull request, reply with:
@SocketSecurity ignore jspdf@3.0.1
Or ignore all future alerts with:
@SocketSecurity ignore-all

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant