Skip to content

Conversation

@james-a-morris
Copy link
Contributor

No description provided.

Signed-off-by: james-a-morris <jaamorris@cs.stonybrook.edu>
@socket-security
Copy link

socket-security bot commented Apr 18, 2024

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@babel/runtime@7.17.2 None +1 198 kB nicolo-ribaudo
npm/@consensys/linea-sdk@0.1.6 Transitive: environment, eval, filesystem, network, shell +12 35.7 MB victorien-gauch
npm/@defi-wonderland/smock@2.3.4 Transitive: environment, eval, filesystem, network +25 10.4 MB 0xgorilla
npm/@ensdomains/ens@0.4.5 Transitive: filesystem, network, unsafe +6 13 MB makoto_inoue
npm/@ensdomains/resolver@0.2.4 None 0 5.02 MB nickjohnson
npm/@eth-optimism/contracts@0.5.40 None 0 1.97 MB optibot
npm/@eth-optimism/core-utils@0.12.0 None +1 211 kB karlfloersch
npm/@ethereumjs/common@2.6.2 None +1 2.55 MB ralxz
npm/@ethereumjs/tx@3.5.0 None 0 421 kB holgerd77
npm/@ethersproject/hardware-wallets@5.7.0 Transitive: environment, filesystem, shell +14 10.6 MB ricmoo
npm/@ethersproject/hdnode@5.5.0 None 0 81 kB ricmoo
npm/@ethersproject/json-wallets@5.5.0 None 0 125 kB ricmoo
npm/@ethersproject/pbkdf2@5.5.0 None 0 17.4 kB ricmoo
npm/@ethersproject/solidity@5.5.0 None 0 23.2 kB ricmoo
npm/@ethersproject/wallet@5.5.0 None 0 55.5 kB ricmoo
npm/@ethersproject/wordlists@5.5.0 None 0 390 kB ricmoo
npm/@ledgerhq/devices@5.51.1 None 0 117 kB gre
npm/@ledgerhq/errors@5.50.0 None 0 78 kB gre
npm/@ledgerhq/hw-transport@5.26.0 None 0 96.7 kB gre
npm/@ledgerhq/logs@5.50.0 None 0 27.4 kB gre
npm/@matterlabs/hardhat-zksync-deploy@0.6.3 filesystem 0 52.5 kB npm-matterlabs
npm/@matterlabs/hardhat-zksync-solc@1.1.4 filesystem, shell Transitive: environment, network, unsafe +67 45.6 MB npm-matterlabs
npm/@matterlabs/hardhat-zksync-upgradable@0.1.0 filesystem Transitive: environment, network, shell +20 3.24 MB npm-matterlabs
npm/@matterlabs/hardhat-zksync-verify@0.2.0 Transitive: environment, filesystem, network, shell +12 901 kB npm-matterlabs
npm/@matterlabs/zksync-contracts@0.2.4 None +2 3.69 MB vladbochok
npm/@nomicfoundation/ethereumjs-evm@1.0.0 environment, eval Transitive: filesystem, network +9 2.78 MB fvictorio
npm/@nomicfoundation/ethereumjs-util@8.0.0 None +5 363 kB fvictorio
npm/@nomicfoundation/hardhat-verify@1.0.3 environment +5 398 kB fvictorio
npm/@nomiclabs/hardhat-ethers@2.2.3 None 0 80.9 kB fvictorio
npm/@nomiclabs/hardhat-waffle@2.0.3 None +5 418 kB alcuadrado
npm/@openzeppelin/contracts-upgradeable@4.9.6 None 0 2.11 MB amxx
npm/@openzeppelin/contracts@4.9.6 None 0 2.02 MB frangio
npm/@openzeppelin/hardhat-upgrades@1.22.0 filesystem Transitive: environment +3 483 kB ericglau
npm/@openzeppelin/upgrades-core@1.32.6 filesystem +2 4.07 MB ericglau
npm/@pinata/sdk@2.1.0 Transitive: environment, network +3 7.55 MB polluterofminds
npm/@scroll-tech/contracts@0.1.0 None 0 198 kB turupawn
npm/@truffle/error@0.2.1 None 0 2.71 kB eggplantzzz
npm/@truffle/interface-adapter@0.5.35 Transitive: filesystem, network, shell +23 6.92 MB eggplantzzz
npm/@typechain/ethers-v5@11.0.0 filesystem Transitive: environment +6 1.13 MB ethereum-ts-bot
npm/@typechain/hardhat@8.0.0 filesystem Transitive: environment, network +21 52.6 MB ethereum-ts-bot
npm/@types/bn.js@5.1.0 None 0 13.9 kB types
npm/@types/chai@4.3.5 None 0 77.2 kB types
npm/@types/mocha@9.1.0 None 0 96.1 kB types
npm/@types/node@12.20.46 None 0 758 kB types
npm/@typescript-eslint/eslint-plugin@4.33.0 Transitive: environment, filesystem +11 4.93 MB jameshenry
npm/@uma/common@2.34.0 environment, filesystem Transitive: network, shell +95 151 MB mrice32
npm/@uma/contracts-node@0.4.17 None 0 69 MB mrice32
npm/@uma/core@2.56.0 filesystem +1 156 MB mrice32
npm/abstract-level@1.0.3 None 0 484 kB vweevers
npm/aes-js@4.0.0-beta.5 None 0 738 kB ricmoo
npm/ansi-styles@3.2.1 None +1 36.6 kB sindresorhus
npm/arb-bridge-eth@0.7.4 None 0 25.7 MB fredlacs
npm/arb-bridge-peripherals@1.0.5 None +2 24.2 MB fredlacs
npm/async-eventemitter@0.2.4 None 0 19.2 kB ahultgren
npm/axios@1.6.2 network Transitive: filesystem +2 1.87 MB jasonsaayman
npm/bignumber.js@8.1.1 None 0 402 kB mikemcl
npm/cbor@8.1.0 None +1 206 kB hildjj
npm/chai@4.3.7 None 0 752 kB chai
npm/chokidar@3.5.3 environment, filesystem 0 90.1 kB paulmillr
npm/compare-versions@6.1.0 None 0 55.2 kB omichelsen
npm/concat-stream@1.6.2 None 0 9.56 kB mafintosh
npm/debug@4.3.4 environment +1 49.2 kB qix
npm/enquirer@2.3.6 environment 0 197 kB jonschlinkert
npm/eslint-config-prettier@8.4.0 None 0 18.1 kB lydell
npm/eslint-config-standard@16.0.3 None 0 16.4 kB linusu
npm/eslint-plugin-import@2.25.4 filesystem, unsafe 0 1.04 MB ljharb
npm/eslint-plugin-node@11.1.0 filesystem +2 652 kB mysticatea
npm/eslint-plugin-prettier@3.4.1 filesystem 0 52.5 kB bpscott
npm/eslint-plugin-promise@5.2.0 None 0 42.5 kB xjamundx
npm/eslint@7.32.0 filesystem +6 3.72 MB eslintbot
npm/eth-ens-namehash@2.0.8 None 0 254 kB danfinlay
npm/eth-sig-util@3.0.1 None 0 51.8 kB gudahtt
npm/ethereum-cryptography@1.2.0 None +1 807 kB paulmillr
npm/ethereum-waffle@3.4.0 None 0 20.3 kB ethworks
npm/ethereumjs-abi@0.6.8 None 0 68.4 kB holgerd77
npm/ethereumjs-util@7.1.4 None +5 492 kB holgerd77
npm/ethereumjs-wallet@1.0.2 None +5 348 kB ralxz
npm/ethers@5.7.2 None 0 10.7 MB ricmoo
npm/find-up@2.1.0 None 0 4.8 kB sindresorhus
npm/follow-redirects@1.15.4 network 0 29.4 kB rubenverborgh
npm/form-data@2.5.1 filesystem, network +1 68.7 kB alexindigo
npm/fs-extra@11.1.1 None 0 59.5 kB ryanzim
npm/gaxios@5.0.2 environment, network +1 96.2 kB google-wombot
npm/glob@7.2.0 filesystem Transitive: environment +2 71.9 kB isaacs
npm/google-auth-library@8.5.2 environment, filesystem, shell 0 492 kB google-wombot
npm/hardhat-deploy@0.11.12 environment, filesystem +3 12.4 MB wighawag
npm/hardhat-gas-reporter@1.0.8 filesystem 0 73.1 kB cgewecke
npm/hardhat@2.14.0 environment, filesystem, network, shell Transitive: eval, unsafe +68 44.9 MB fvictorio
npm/husky@4.3.8 environment, filesystem, shell +1 66.4 kB typicode
npm/keccak@3.0.3 None +1 1.2 MB fanatid
npm/mime-types@2.1.34 None 0 18 kB dougwilson
npm/mkdirp@0.5.5 filesystem 0 7.53 kB isaacs
npm/mocha@10.2.0 environment, eval, filesystem +3 2.11 MB juergba
npm/prettier-plugin-solidity@1.0.0-beta.19 None 0 696 kB janther
npm/prettier@2.5.1 environment, eval, filesystem, unsafe 0 21 MB sosukesuzuki
npm/pretty-quick@2.0.2 filesystem Transitive: environment +2 77.3 kB azz
npm/proper-lockfile@4.1.2 None 0 29.9 kB hugomrdias
npm/qs@6.10.3 None 0 216 kB ljharb
npm/readable-stream@3.6.0 environment +1 132 kB matteo.collina
npm/secp256k1@4.0.3 None +1 2.69 MB fanatid
npm/semver@7.3.5 None 0 88.2 kB isaacs
npm/solhint@3.3.7 filesystem Transitive: environment +2 236 kB fvictorio
npm/solidity-ast@0.4.56 None 0 238 kB frangio
npm/solidity-coverage@0.7.20 filesystem Transitive: environment +4 195 kB cgewecke
npm/strip-ansi@4.0.0 None +1 6.96 kB sindresorhus
npm/table@6.8.1 None 0 335 kB gajus-table
npm/tar-fs@2.0.1 filesystem 0 27.7 kB mafintosh
npm/tar-stream@1.6.2 filesystem 0 26.8 kB mafintosh
npm/ts-node@10.6.0 environment, filesystem, unsafe 0 591 kB cspotcode
npm/typechain@8.1.1 filesystem Transitive: environment +5 1.04 MB ethereum-ts-bot
npm/typescript@4.6.2 None 0 64.7 MB typescript-bot
npm/undici@5.21.0 environment, network, unsafe 0 1.08 MB matteo.collina
npm/web3-bzz@1.8.2 Transitive: filesystem, network, shell +3 467 kB jdevcs
npm/web3-core-helpers@1.8.2 None 0 60.4 kB jdevcs
npm/web3-core-method@1.10.0 None +4 1.16 MB jdevcs
npm/web3-core-promievent@1.8.2 None 0 6.77 kB jdevcs
npm/web3-core-requestmanager@1.10.0 None 0 42.2 kB jdevcs
npm/web3-core-subscriptions@1.10.0 None 0 32.4 kB jdevcs
npm/web3-core@1.8.2 None 0 24 kB jdevcs
npm/web3-eth-abi@1.8.2 None 0 50.8 kB jdevcs
npm/web3-eth-accounts@1.10.0 None 0 66.1 kB jdevcs
npm/web3-eth-contract@1.10.0 None +5 1.18 MB jdevcs
npm/web3-eth-ens@1.10.0 None +5 1.5 MB jdevcs
npm/web3-eth-iban@1.10.0 None +4 1.11 MB jdevcs
npm/web3-eth-personal@1.8.2 None 0 19.4 kB jdevcs
npm/web3-eth@1.8.2 None +2 146 kB jdevcs
npm/web3-net@1.8.2 None 0 9.26 kB jdevcs
npm/web3-shh@1.8.2 None 0 26 kB jdevcs
npm/web3-utils@1.8.2 None +4 1.25 MB jdevcs
npm/web3@1.7.0 None 0 5.72 MB spacesailor
npm/winston@3.11.0 filesystem, network 0 268 kB dabh
npm/yargs@4.8.1 environment, filesystem 0 175 kB bcoe
npm/zksync-web3@0.14.3 environment 0 876 kB stanislavbezkor

🚮 Removed packages: npm/@babel/code-frame@7.12.11, npm/@jridgewell/sourcemap-codec@1.4.15, npm/@noble/secp256k1@1.7.1, npm/@nodelib/fs.stat@2.0.5, npm/@protobufjs/aspromise@1.1.2, npm/@types/minimatch@3.0.5, npm/@uniswap/lib@4.0.1-alpha, npm/acorn-jsx@5.3.2, npm/ansi-colors@4.1.1, npm/array-back@2.0.0, npm/asn1.js@5.4.1, npm/asn1@0.2.6, npm/assert-plus@1.0.0, npm/base-x@3.0.9, npm/base64-js@1.5.1, npm/braces@3.0.2, npm/brorand@1.1.0, npm/browser-readablestream-to-it@1.0.3, npm/browserify-rsa@4.1.0, npm/buffer@6.0.3, npm/caseless@0.12.0, npm/catering@2.1.1, npm/cipher-base@1.0.4, npm/clone@2.1.2, npm/color-name@1.1.3, npm/console-control-strings@1.1.0, npm/cross-spawn@7.0.3, npm/decamelize@1.2.0, npm/deep-eql@4.1.3, npm/deep-extend@0.6.0, npm/deep-is@0.1.4, npm/domutils@2.8.0, npm/ecdsa-sig-formatter@1.0.11, npm/encoding@0.1.13, npm/end-of-stream@1.4.4, npm/error-ex@1.3.2, npm/es6-promise@4.2.8, npm/espree@7.3.1, npm/esrecurse@4.3.0, npm/estraverse@4.3.0, npm/eth-query@2.1.2, npm/evp_bytestokey@1.0.3, npm/extsprintf@1.3.0, npm/fast-deep-equal@3.1.3, npm/fast-levenshtein@2.0.6, npm/fill-range@7.0.1, npm/find-yarn-workspace-root@2.0.0, npm/fsevents@2.3.2, npm/get-caller-file@2.0.5, npm/get-func-name@2.0.2, npm/glob-parent@5.1.2, npm/has-symbols@1.0.3, npm/has@1.0.3, npm/hosted-git-info@2.8.9, npm/ieee754@1.2.1, npm/import-fresh@3.3.0, npm/ini@1.3.8, npm/is-buffer@2.0.5, npm/is-regex@1.1.4, npm/is-stream@1.1.0, npm/is-string@1.0.7, npm/is-symbol@1.0.4, npm/is-typedarray@1.0.0, npm/is-weakref@1.0.2, npm/js-tokens@4.0.0, npm/json-rpc-random-id@1.0.1, npm/kind-of@6.0.3, npm/lower-case@1.1.4, npm/merge2@1.4.1, npm/mimic-response@1.0.1, npm/mkdirp-classic@0.5.3, npm/module-error@1.0.2, npm/no-case@2.3.2, npm/normalize-path@3.0.0, npm/object-assign@4.1.1, npm/object-inspect@1.12.0, npm/object-keys@1.1.1, npm/parse5-htmlparser2-tree-adapter@6.0.1, npm/path-key@3.1.1, npm/path-parse@1.0.7, npm/picomatch@2.3.1, npm/pify@3.0.0, npm/process@0.11.10, npm/queue-microtask@1.2.3, npm/safer-buffer@2.1.2, npm/set-blocking@2.0.0, npm/sha.js@2.4.11, npm/signal-exit@3.0.7, npm/source-map@0.6.1, npm/statuses@1.5.0, npm/strip-json-comments@3.1.1, npm/through@2.3.8, npm/tmp@0.0.33, npm/to-regex-range@5.0.1, npm/type-check@0.4.0, npm/type-detect@4.0.8, npm/typical@2.6.1, npm/uc.micro@1.0.6, npm/uint8arrays@2.1.10, npm/unpipe@1.0.0, npm/upper-case@1.1.3, npm/util-deprecate@1.0.2, npm/vary@1.1.2, npm/which@2.0.2, npm/xhr@2.6.0, npm/xtend@4.0.2, npm/yaml@1.10.2, npm/yargs-parser@20.2.4

View full report↗︎

@socket-security
Copy link

socket-security bot commented Apr 18, 2024

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSource
Install scripts npm/web3@1.7.0
  • Install script: postinstall
  • Source: echo "WARNING: the web3-shh and web3-bzz api will be deprecated in the next version"
Install scripts npm/husky@4.3.8
  • Install script: postinstall
  • Source: opencollective-postinstall || exit 0
Install scripts npm/husky@4.3.8
  • Install script: install
  • Source: node husky install
Install scripts npm/web3-bzz@1.8.2
  • Install script: postinstall
  • Source: echo "WARNING: the web3-bzz api will be deprecated in the next version"
Install scripts npm/web3-shh@1.8.2
  • Install script: postinstall
  • Source: echo "WARNING: the web3-shh api will be deprecated in the next version"
Install scripts npm/web3@1.8.2
  • Install script: postinstall
  • Source: echo "Web3.js 4.x alpha has been released for early testing and feedback. Checkout doc at https://docs.web3js.org/ "
Install scripts npm/web3@1.10.0
  • Install script: postinstall
  • Source: echo "Web3.js 4.x alpha has been released for early testing and feedback. Checkout doc at https://docs.web3js.org/ "
Install scripts npm/web3-bzz@1.10.0
  • Install script: postinstall
  • Source: echo "WARNING: the web3-bzz api will be deprecated in the next version"
Install scripts npm/web3-shh@1.10.0
  • Install script: postinstall
  • Source: echo "WARNING: the web3-shh api will be deprecated in the next version"
Install scripts npm/arb-bridge-eth@0.7.4
  • Install script: postinstall
  • Source: $npm_execpath run clean:build
Install scripts npm/arb-bridge-peripherals@1.0.5
  • Install script: postinstall
  • Source: $npm_execpath run clean:build

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/web3@1.7.0
  • @SocketSecurity ignore npm/husky@4.3.8
  • @SocketSecurity ignore npm/web3-bzz@1.8.2
  • @SocketSecurity ignore npm/web3-shh@1.8.2
  • @SocketSecurity ignore npm/web3@1.8.2
  • @SocketSecurity ignore npm/web3@1.10.0
  • @SocketSecurity ignore npm/web3-bzz@1.10.0
  • @SocketSecurity ignore npm/web3-shh@1.10.0
  • @SocketSecurity ignore npm/arb-bridge-eth@0.7.4
  • @SocketSecurity ignore npm/arb-bridge-peripherals@1.0.5

@james-a-morris
Copy link
Contributor Author

Merging with offline signoff from @nicholaspai

@james-a-morris james-a-morris merged commit 1bb60f2 into master Apr 19, 2024
@james-a-morris james-a-morris deleted the james/bump-constants branch April 19, 2024 13:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants