Update changesets/action action to v1.8.0 #1229
Pull Request #1229 Alerts: Complete with warnings WARNING: Free tier size exceeded
| Report | Status | Message |
|---|---|---|
| PR #1229 Alerts | Found 6 project alerts |
Pull request alerts notify when new issues are detected between the diff of the pull request and it's target branch.
Details
Caution
Review the following alerts detected in dependencies.
According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.
| Action | Severity | Alert (click "▶" to expand/collapse) |
|---|---|---|
| Block | Potential code anomaly (AI signal): npm
|
|
| Block | Potential code anomaly (AI signal): npm
|
|
| Block | Low CVE: Elliptic allows BER-encoded signaturesCVE: GHSA-49q7-c7j4-3p7m Elliptic allows BER-encoded signatures (LOW) Affected versions: >= 5.2.1 < 6.5.7 Patched version: 6.5.7 From: ℹ Read more on: This package | This alert | What is a mild CVE?
|
|
| Block | Low CVE: Elliptic's ECDSA missing check for whether leading bit of r and s is zeroCVE: GHSA-977x-g7h5-7qgw Elliptic's ECDSA missing check for whether leading bit of r and s is zero (LOW) Affected versions: >= 2.0.0 < 6.5.7 Patched version: 6.5.7 From: ℹ Read more on: This package | This alert | What is a mild CVE?
|
|
| Block | Low CVE: Elliptic's EDDSA missing signature length checkCVE: GHSA-f7q4-pwc6-w24p Elliptic's EDDSA missing signature length check (LOW) Affected versions: >= 4.0.0 < 6.5.7 Patched version: 6.5.7 From: ℹ Read more on: This package | This alert | What is a mild CVE?
|
|
| Block | Low CVE: Elliptic's verify function omits uniqueness validationCVE: GHSA-434g-2637-qmqr Elliptic's verify function omits uniqueness validation (LOW) Affected versions: < 6.5.6 Patched version: 6.5.6 From: ℹ Read more on: This package | This alert | What is a mild CVE?
|