Skip to content

deps: periodic dependency update - #200

Merged
qw-in merged 27 commits into
mainfrom
quinn/deps-2026-08-24
Aug 24, 2026
Merged

deps: periodic dependency update#200
qw-in merged 27 commits into
mainfrom
quinn/deps-2026-08-24

Conversation

@qw-in

@qw-in qw-in commented Aug 24, 2026

Copy link
Copy Markdown
Member

Periodic dependency and security update for the examples

qw-in and others added 27 commits August 24, 2026 14:09
Update @astrojs/check, @astrojs/node, @fontsource-variable/figtree, @fontsource/ibm-plex-mono, astro, and prettier to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @anthropic-ai/claude-agent-sdk and @types/node to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run typecheck.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard to the 1.10.0 stable release, and bump @types/node and eve to the greatest minor version within the 7-day cooldown window.

Verified with npm install, npm run typecheck, and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/node and @types/node to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build (tsc --noEmit).

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fastify/autoload, fastify, prettier, and tsx to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build (tsc).

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update firebase-functions and firebase-tools to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run check (tsc).

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @langchain/openai and @types/node to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run typecheck.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard to the 1.10.0 stable release and bump @types/node to the greatest minor version within the 7-day cooldown window.

Verified with npm install. npm run typecheck fails on main before this change too (pre-existing @arcjet/guard/mastra/v1 module resolution and implicit-any errors unrelated to these bumps), so it is not new breakage.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @nestjs/common, @nestjs/core, @nestjs/platform-express, and prettier to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build (nest build).

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @ai-sdk/openai, @ai-sdk/react, @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @hookform/resolvers, @playwright/test, @types/react, @types/react-dom, ai, next, react, react-dom, and react-hook-form to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard to the 1.10.0 stable release, and bump @types/node, @types/react, @types/react-dom, ai, next, react, react-dom, and workflow to the greatest minor version within the 7-day cooldown window.

Verified with npm install, npm run typecheck, and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/inspect, @arcjet/next, @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @types/node, @types/react, @types/react-dom, next, react, and react-dom to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @types/react, @types/react-dom, next, react, and react-dom to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @hookform/resolvers, @types/react, @types/react-dom, next, react, react-dom, and react-hook-form to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @hookform/resolvers, @types/react, @types/react-dom, next, react, react-dom, and react-hook-form to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard and @arcjet/sensitive-info-rampart to the 1.10.0 stable release, and bump @ai-sdk/provider-utils, @types/node, @types/react, @types/react-dom, ai, next, react, and react-dom to the greatest minor version within the 7-day cooldown window.

Verified with npm install, npm run typecheck, and npm run build (with ARCJET_KEY/AI_GATEWAY_API_KEY set locally; the example throws at module load without them, unrelated to this change).

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard, @arcjet/next, and @arcjet/sensitive-info-rampart to the 1.10.0 stable release, and bump @types/node, @types/react, @types/react-dom, next, react, and react-dom to the greatest minor version within the 7-day cooldown window.

Verified with npm install, npm run typecheck, and npm run build (with ARCJET_KEY set locally).

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @types/react, @types/react-dom, next, react, and react-dom to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard and @arcjet/sensitive-info-rampart to the 1.10.0 stable release, and bump @ai-sdk/provider-utils, @types/node, and ai to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run typecheck.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, vue, and vue-tsc to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build (with ARCJET_KEY set locally; the @arcjet/nuxt module throws during nuxt prepare/postinstall without it, unrelated to this change).

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @types/react, @types/react-dom, isbot, react, and react-dom to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/react-router, @react-router/dev, @react-router/node, @react-router/serve, @types/node, @types/react, @types/react-dom, isbot, react, react-dom, and react-router to the greatest minor version within the 7-day cooldown window.

npm install hit an ERESOLVE peer conflict from @react-router/dev@7.18.2 requiring react-router@^7.18.2 before the sibling react-router upgrade landed. Followed AGENTS.md's documented procedure: npm install --legacy-peer-deps followed by a plain npm install, which resolved cleanly with no leftover peer overrides.

Verified with npm install and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, prettier, svelte, and svelte-check to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @tanstack/react-router, @tanstack/react-start, @types/react, @types/react-dom, react, and react-dom to the greatest minor version within the 7-day cooldown window.

Verified with npm install and npm run build (vite build && tsc --noEmit).

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
GHSA-w5hq-g745-h8pq: uuid <11.1.1 has a missing buffer bounds check in v3/v5/v6 when a buf argument is provided. It reaches this example transitively through newman's postman-collection, postman-request, postman-runtime, and serialised-error dependencies (moderate severity per npm audit).

Not directly exploitable here: every call site in those packages uses uuid.v4() with no buf argument, so the affected code path is never reached. Still overrode the transitive uuid to 11.1.1 (patched, CommonJS-compatible) scoped to those four packages, following the same pattern used for firebase-functions' uuid fix, rather than npm audit fix --force which would downgrade newman to 3.9.3.

Verified with npm install, npm audit (0 vulnerabilities, was 7 moderate), npm ls uuid (all copies now 11.1.1), and npm run build (tsc --noEmit).

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Record the root-params type reference generated by next build with Next.js 16.3.1 for nextjs-ai-agent, nextjs-bot-categories, nextjs-guard-policy, and nextjs-sensitive-info. Follow-up to the periodic dependency updates in these examples; next-env.d.ts is a generated file and should not be hand-edited.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Regenerate routeTree.gen.ts (alphabetical route re-sort, no route changes) produced by vite build with the updated @tanstack/react-router. Follow-up to the periodic dependency update; routeTree.gen.ts is a generated file and should not be hand-edited.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@qw-in qw-in self-assigned this Aug 24, 2026

@arcjet-review arcjet-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Arcjet Review — 🟡 Medium Risk

Decision: Needs Review

Rationale: This PR updates dependencies across many example applications and refreshes generated framework files. The changes are mostly version bumps, including a security-motivated override for transitive uuid usage in the express-newman example, and no hardcoded secrets or direct application security regressions are visible in the diff. However, dependency changes are an escalation trigger, the scope spans many frameworks, and some updates touch security-sensitive/example protection packages such as Arcjet guard, sensitive-info-rampart, Next.js, React Router, Firebase Functions, and pre-1.0 packages where minor version bumps can carry breaking changes. I am not confident enough to approve without human verification that installs, lockfile state, and example type/build/test suites pass.

Summary of Changes

Updates package dependencies across multiple examples, adds npm overrides to force uuid 11.1.1 under Newman/Postman transitive packages, refreshes Next.js generated type references, and regenerates the TanStack Start route tree with reordered route declarations.

Escalation Triggers

  • Dependency Changes: Multiple package.json files under examples were changed, including runtime framework, security/protection, AI, and testing dependencies.

Review Focus Areas

Notes

No direct code paths for authentication, input handling, cryptography, or secret management were changed in the visible diff. The primary residual risk is dependency resolution and runtime compatibility across the affected examples.

Path filtering: 24 files excluded by ignore paths. 29 of 53 files included in review.

Review: 8f105b81 | Model: openai/gpt-5.5 | Powered by Arcjet Review

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​next@​16.2.6 ⏵ 16.3.161 -2100 +4090 +19970
Updatednpm/​@​arcjet/​sensitive-info-rampart@​1.10.0-rc.0 ⏵ 1.10.080 +110010092 +370
Updatednpm/​@​anthropic-ai/​claude-agent-sdk@​0.3.233 ⏵ 0.3.234100 +110092 +110070
Updatednpm/​@​ai-sdk/​openai@​3.0.84 ⏵ 3.0.9773 +810088 +198100
Updatednpm/​@​ai-sdk/​react@​3.0.226 ⏵ 3.0.25999 +510075 +198100
Updatednpm/​@​types/​react-dom@​19.2.3 ⏵ 19.2.4100 +110075 +188 -3100
Updatednpm/​@​ai-sdk/​provider-utils@​4.0.38 ⏵ 5.0.2794 -310076 +198100
Updatednpm/​@​types/​react@​19.2.15 ⏵ 19.2.181001007992100
Updatednpm/​@​astrojs/​check@​0.9.9 ⏵ 0.9.101001008090 -1100
Updatednpm/​eve@​0.31.0 ⏵ 0.38.399 +1100100 +198 +180
Updatednpm/​@​arcjet/​guard@​1.10.0-rc.0 ⏵ 1.10.081 +3100100 +196 +1100
Updatednpm/​@​fontsource-variable/​figtree@​5.2.10 ⏵ 5.3.094 +11008189 +690
Updatednpm/​tsx@​4.23.0 ⏵ 4.23.1210010081 +194 -1100
Updatednpm/​@​astrojs/​node@​11.1.1 ⏵ 11.1.2100 +110082 +197 +1100
Updatednpm/​@​fontsource/​ibm-plex-mono@​5.2.7 ⏵ 5.3.010010085 +183 -490
Updatednpm/​react@​19.2.6 ⏵ 19.2.81001008497100
Updatednpm/​workflow@​4.8.1 ⏵ 4.8.399 +11008699 +1100
Updatednpm/​firebase-tools@​15.23.0 ⏵ 15.27.086 +1010010099100
Updatednpm/​@​tanstack/​react-router@​1.170.17 ⏵ 1.170.2992 +1710087 +498 +1100
Updatednpm/​svelte@​5.56.4 ⏵ 5.56.988 +11008798 +2100
Updatednpm/​firebase-functions@​7.2.5 ⏵ 7.3.295 -210087 +198 +8100
Updatednpm/​@​tanstack/​react-start@​1.168.27 ⏵ 1.168.469910088 +598 +1100
Updatednpm/​astro@​7.2.1 ⏵ 7.2.29810088 +198100
Updatednpm/​isbot@​5.2.0 ⏵ 5.2.1100 +110010091 -3100
Updatednpm/​vue-tsc@​3.3.7 ⏵ 3.3.101001009197100
Updatednpm/​react-dom@​19.2.6 ⏵ 19.2.81001009298100
Updatednpm/​@​fastify/​autoload@​6.4.0 ⏵ 6.5.09910010094 +3100
Updatednpm/​react-hook-form@​7.81.0 ⏵ 7.85.0100 +1100100 +194 -1100
Updatednpm/​@​nestjs/​common@​11.1.28 ⏵ 11.2.1100 +110010095 +1100
Updatednpm/​@​nestjs/​core@​11.1.28 ⏵ 11.2.199 +110010095 +1100
Updatednpm/​svelte-check@​4.7.2 ⏵ 4.7.699 +110010097 +1100
Updatednpm/​@​nestjs/​platform-express@​11.1.28 ⏵ 11.2.1100 +110010097100
See 7 more rows in the dashboard

View full report

@arcjet-review arcjet-review Bot removed the needs review Awaiting human review label Aug 24, 2026
@socket-security

Copy link
Copy Markdown

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. It is recommended to resolve "Warn" alerts too. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Medium
Potential vulnerability: npm @fastify/autoload with risk level "medium"

Location: Package overview

From: examples/fastify/package-lock.jsonnpm/@fastify/autoload@6.5.0

ℹ Read more on: This package | This alert | Navigating potential vulnerabilities

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: It is advisable to proceed with caution. Engage in a review of the package's security aspects and consider reaching out to the package maintainer for the latest information or patches.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@fastify/autoload@6.5.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm @workflow/core is 78.0% likely risky

Notes: High-risk security issue: the code contains a direct eval sink in revive(str) used for v1 compatibility (v1Compat). If attacker-controlled serialized strings can reach this path, it enables arbitrary JavaScript execution (RCE). Other portions (framing/encryption/streaming) look like standard protocol logic, and no clear exfiltration/mining/backdoor behavior is present in the provided fragment.

Confidence: 0.78

Severity: 0.86

From: examples/nextjs-ai-agent/package-lock.jsonnpm/workflow@4.8.3npm/@workflow/core@4.8.3

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@workflow/core@4.8.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm @workflow/web is 62.0% likely risky

Notes: Overall behavior matches a legitimate workflow orchestration runtime (network I/O, streaming, schema-driven parsing, optional encryption). However, it contains a direct eval-based dynamic execution primitive (revive(str) → (0, eval)(...)) used in a legacy/v1Compat hydration path. If untrusted data can reach the string passed to revive(), this can enable arbitrary code execution. Step execution is also dynamically dispatched based on queue-provided step identifiers, which is security-critical. No explicit overt malware (hardcoded backdoors/cryptomining/exfiltration endpoints) is evident in the provided fragment, but the eval sink makes the module high-risk unless strict trust boundaries ensure revive() input is never attacker-influenced.

Confidence: 0.62

Severity: 0.85

From: examples/nextjs-ai-agent/package-lock.jsonnpm/workflow@4.8.3npm/@workflow/web@4.1.19

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@workflow/web@4.1.19. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm eve is 78.0% likely risky

Notes: High security risk: the module includes an explicit JavaScript parsing engine that evaluates attacker-controlled input via eval(), and it also includes YAML tag handling that can dynamically construct functions using the Function(...) constructor. If attacker-controlled front-matter or YAML (with explicit function tags) reaches these code paths, it can lead to arbitrary code execution. Additionally, its file-reading helper can contribute to sensitive file access if paths are attacker-influenced.

Confidence: 0.78

Severity: 0.92

From: examples/eve-agent/package-lock.jsonnpm/eve@0.38.3

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/eve@0.38.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential vulnerability: npm firebase-tools with risk level "medium"

Location: Package overview

From: examples/firebase-functions/package-lock.jsonnpm/firebase-tools@15.27.0

ℹ Read more on: This package | This alert | Navigating potential vulnerabilities

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: It is advisable to proceed with caution. Engage in a review of the package's security aspects and consider reaching out to the package maintainer for the latest information or patches.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/firebase-tools@15.27.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm firebase-tools is 62.0% likely risky

Notes: No direct evidence of stealthy malware (no network/exfiltration/persistence/file tampering observed in this snippet). However, the module is security-sensitive because it can execute an executable specified by process.argv[2] and then executes a derived binary path taken from JSON output without validation/allowlisting. If an attacker can influence argv[2] or the executed tool’s output in the environment, this can become arbitrary command execution in the context of the user. Additionally, unhandled JSON.parse failures introduce reliability/DoS risk, and terminal output derived from child stderr could carry terminal control-sequence risk.

Confidence: 0.62

Severity: 0.70

From: examples/firebase-functions/package-lock.jsonnpm/firebase-tools@15.27.0

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/firebase-tools@15.27.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm firebase-tools is 65.0% likely risky

Notes: No explicit malware or exfiltration behavior is visible in this snippet, but the module is a powerful local execution driver. It can execute arbitrary OS commands from caller-controlled spec fields and can execute dynamically generated JavaScript via node -e based on hook-related inputs. If any upstream supply-chain inputs (spec/bundle/hook or the hook generator) are attacker-controlled, this becomes an effective arbitrary code execution vector with high security risk. Review and harden trust boundaries around spec, genHookScript, and the integrity of hooks_1.BUNDLE_PATH before parsing.

Confidence: 0.65

Severity: 0.72

From: examples/firebase-functions/package-lock.jsonnpm/firebase-tools@15.27.0

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/firebase-tools@15.27.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential vulnerability: npm next with risk level "medium"

Location: Package overview

From: examples/nextjs-bot-protection/package-lock.jsonnpm/next@16.3.1

ℹ Read more on: This package | This alert | Navigating potential vulnerabilities

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: It is advisable to proceed with caution. Engage in a review of the package's security aspects and consider reaching out to the package maintainer for the latest information or patches.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/next@16.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm next is 75.0% likely risky

Notes: This code is a manifest loader that can either JSON-parse a manifest or (when useEval is enabled) execute the manifest file contents as JavaScript via vm.runInNewContext. Executing untrusted file content is a significant risk, especially because the VM context is not explicitly hardened and exposes environment-derived data (NEXT_DEPLOYMENT_ID). If an attacker can control or tamper with the manifest file, this module could enable code execution or data exposure; at minimum it substantially increases attack surface compared to pure JSON parsing.

Confidence: 0.75

Severity: 0.70

From: examples/nextjs-bot-protection/package-lock.jsonnpm/next@16.3.1

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/next@16.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm playwright-core is 70.0% likely risky

Notes: No evidence of obfuscated or overtly malicious logic (no persistence, exfiltration, or credential theft) appears in the provided snippet. However, it implements a high-risk supply-chain pattern: it downloads an MSI from a URL provided at runtime and installs it silently via msiexec without any integrity or origin verification. If an attacker can influence $args[0] or the referenced endpoint, this script can facilitate arbitrary MSI payload execution on the host.

Confidence: 0.70

Severity: 0.72

From: examples/nextjs/package-lock.jsonnpm/@playwright/test@1.62.1npm/playwright-core@1.62.1

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/playwright-core@1.62.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm playwright-core is 76.0% likely risky

Notes: This module is a straightforward installer wrapper, but it has a high supply-chain trust boundary risk: it downloads an MSI from a caller-provided URL and silently executes it via msiexec without any integrity/signature validation or URL allowlisting. There is no clear evidence of hidden malware in the visible code, but the execution pattern can enable malicious installer delivery if the URL/contents are compromised or attacker-controlled.

Confidence: 0.76

Severity: 0.74

From: examples/nextjs/package-lock.jsonnpm/@playwright/test@1.62.1npm/playwright-core@1.62.1

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/playwright-core@1.62.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm playwright-core is 78.0% likely risky

Notes: This module is a generic “download-and-silent-install MSI” bootstrapper where the critical control point (the download URL) is fully caller-controlled and the fragment lacks any integrity/signature verification of the downloaded MSI before executing it via msiexec. While there is no explicit backdoor/exfiltration code in the fragment, the combination of (a) arbitrary remote MSI acquisition and (b) silent installer execution makes it a high-risk supply-chain pattern if $args[0] can be influenced or if download provenance cannot be guaranteed externally.

Confidence: 0.78

Severity: 0.78

From: examples/nextjs/package-lock.jsonnpm/@playwright/test@1.62.1npm/playwright-core@1.62.1

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/playwright-core@1.62.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm seroval is 78.0% likely risky

Notes: This module fragment is structurally high risk for supply-chain/security contexts because it generates JavaScript source and includes an explicit (0, eval)(source) deserialization entry point. If an attacker can influence the serialized string passed to deserialize()/compile paths or the plugin set used during reconstruction, it can lead to direct arbitrary code execution. No clear evidence of covert malware (e.g., exfiltration/backdoors) is visible in the provided code; the dominant concern is the intentional code-generation/evaluation design combined with plugin extensibility.

Confidence: 0.78

Severity: 0.85

From: examples/tanstack-start/package-lock.jsonnpm/@tanstack/react-router@1.170.29npm/@tanstack/react-start@1.168.46npm/seroval@1.6.3

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/seroval@1.6.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm seroval is 75.0% likely risky

Notes: No clear evidence of overt malware (e.g., network exfiltration, persistence, or credential theft) is visible in this fragment. However, the module is security-critical because deserialization performs direct JavaScript execution via (0, eval)(source) and because a plugin system executes attacker-controlled plugin code when untrusted plugins are used. Therefore, if serialized inputs or plugins are not strictly trusted, the security risk is high and can result in arbitrary code execution.

Confidence: 0.75

Severity: 0.87

From: examples/tanstack-start/package-lock.jsonnpm/@tanstack/react-router@1.170.29npm/@tanstack/react-start@1.168.46npm/seroval@1.6.3

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/seroval@1.6.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm seroval is 84.0% likely risky

Notes: This package is fundamentally dangerous when handling untrusted input because it includes an explicit eval-based deserialization entry point (deserialize(source) -> eval). If an attacker can supply or influence the serialized payload, this can lead to arbitrary JavaScript execution (RCE). Additionally, the module reconstructs asynchronous/control-flow primitives and supports non-sandboxed plugins, further expanding execution risk. While the fragment shows no obvious exfiltration or system sabotage code, the eval sink and dynamic reconstruction design make the supply-chain/security risk very high unless inputs and plugins are strictly trusted and controlled.

Confidence: 0.84

Severity: 0.94

From: examples/tanstack-start/package-lock.jsonnpm/@tanstack/react-router@1.170.29npm/@tanstack/react-start@1.168.46npm/seroval@1.6.3

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/seroval@1.6.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm seroval is 82.0% likely risky

Notes: No overt covert malware (network/file/process activity) is evident in this fragment; however, the deserialization API includes a direct (0, eval)(source) sink, and the overall design generates executable JavaScript from serialized data and complex constructs. If serialized payloads or plugins are not fully trusted, this creates a high-severity arbitrary code execution risk.

Confidence: 0.82

Severity: 0.90

From: examples/tanstack-start/package-lock.jsonnpm/@tanstack/react-router@1.170.29npm/@tanstack/react-start@1.168.46npm/seroval@1.6.3

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/seroval@1.6.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm tsx is 78.0% likely risky

Notes: The primary security issue in this module is direct dynamic code execution: (0, eval) is called on substrings derived from the caller-controlled input during parsing. If parse() is ever invoked with untrusted or partially trusted input, this enables arbitrary JavaScript execution in the consumer environment. The embedded WebAssembly is opaque but also determines what content becomes evaluated and what slices are produced. No explicit exfiltration or filesystem/network activity is visible in this wrapper, but the eval sink makes the overall security posture high-risk.

Confidence: 0.78

Severity: 0.90

From: examples/fastify/package-lock.jsonnpm/tsx@4.23.12

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/tsx@4.23.12. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Potential security risk (AI signal): npm tsx is 62.0% likely risky

Notes: This module is a runtime execution hook that patches Node’s REPL eval to transform user-entered code with esbuild (including TS parsing) and rewrites require to global.require in the transformed output before executing it via the original eval. While there is no direct evidence of network exfiltration or credential theft within this snippet, the pattern is strongly suspicious because it expands execution capabilities and alters module-loading semantics at runtime, with silent error suppression reducing observability.

Confidence: 0.62

Severity: 0.70

From: examples/fastify/package-lock.jsonnpm/tsx@4.23.12

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/tsx@4.23.12. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm @smithy/core is 65.0% likely to have a medium risk anomaly

Notes: The code implements a conventional, well-structured event-stream unmarshalling pipeline with explicit handling for error, exception, and event message types. The primary security considerations are: potential exposure of header/body content through thrown errors, reliance on the deserializer contract (notably the $unknown flag), and ensuring that downstream consumers appropriately trust the deserialized payloads. In a supply-chain context, ensure that eventStreamCodec, deserializer implementations, and error handling are trusted and audited to avoid leaking sensitive metadata, and consider sanitizing error messages in production.

Confidence: 0.65

Severity: 0.60

From: examples/nextjs-ai-agent/package-lock.jsonnpm/workflow@4.8.3npm/@smithy/core@3.33.3

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@smithy/core@3.33.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm @tanstack/react-router is 72.0% likely to have a medium risk anomaly

Notes: Functionally, this is an SSR-only “inject once” script helper. It is not inherently malicious, but it is a powerful code-injection sink: whatever string is passed as children becomes executable JavaScript in the client via dangerouslySetInnerHTML inside a <script> tag. Security impact therefore depends entirely on whether children is strictly trusted (e.g., developer-authored constants) versus attacker-influenced. No network/exfiltration/backdoor behavior is present in the provided fragment.

Confidence: 0.72

Severity: 0.56

From: examples/tanstack-start/package-lock.jsonnpm/@tanstack/react-router@1.170.29

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@tanstack/react-router@1.170.29. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm @tanstack/start-plugin-core is 62.0% likely to have a medium risk anomaly

Notes: No clear indicators of classic malware (exfiltration, reverse shells, credential theft, or code execution) are present in this module. The dominant supply-chain/security risk is build-time: crawl targets and output filenames are influenced by link-derived hrefs and auto-discovered global data without the same strict validation applied to initial page paths. Combined with computed filepath creation (path.join(outputDir, filename)) and lack of explicit enforcement that the final resolved path stays within outputDir, this creates a plausible directory traversal / arbitrary file write risk if href/page/path normalization utilities do not fully eliminate traversal sequences. Additionally, writing fetched HTML verbatim can propagate upstream HTML content into the generated site.

Confidence: 0.62

Severity: 0.58

From: examples/tanstack-start/package-lock.jsonnpm/@tanstack/react-start@1.168.46npm/@tanstack/start-plugin-core@1.171.36

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@tanstack/start-plugin-core@1.171.36. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

See 51 more rows in the dashboard

View full report

@qw-in
qw-in added this pull request to the merge queue Aug 24, 2026
Merged via the queue into main with commit e549a33 Aug 24, 2026
22 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants