Skip to content

Comments

No package.json resolutions to force test with SFW#292

Draft
mathieu-benoit wants to merge 2 commits intomainfrom
sfw-tests
Draft

No package.json resolutions to force test with SFW#292
mathieu-benoit wants to merge 2 commits intomainfrom
sfw-tests

Conversation

@mathieu-benoit
Copy link
Owner

@mathieu-benoit mathieu-benoit commented Feb 15, 2026

No package.json resolutions to force test with Socket Firewall: https://socket.dev/blog/socket-firewall-now-available-in-docker-hardened-images.

So far, not blocked, but getting this:

#34 28.99 === Socket Firewall ===
#34 28.99 
#34 28.99  - 1253 packages fetched successfully
#34 28.99 Potential malware detected with AI scan. Not blocked by sfw-free:
#34 28.99  - jmespath@0.15.0
#34 28.99 
#34 29.86 Warning: Socket Firewall did not detect any package fetch attempts

https://socket.dev/npm/package/jmespath/overview/0.15.0

Note: this also happening in main branch, so not specific to the removal of these resolutions.

I'll keep this PR opened as draft in order to track in the future if SFW can catch/block any issue with npm packages in this repo.

Removed several package resolutions and retained only @types/react-dom.
@mathieu-benoit mathieu-benoit marked this pull request as draft February 15, 2026 19:17
@github-actions
Copy link
Contributor

Overview

Image reference backstage:latest backstage:latest
- digest 7010ea751a43 08410b648e22
- tag latest latest
- provenance fcf6e9b 7029a52
- vulnerabilities critical: 0 high: 1 medium: 1 low: 0 critical: 0 high: 5 medium: 8 low: 2
- platform linux/amd64 linux/amd64
- size 215 MB 216 MB (+1.2 MB)
- packages 1282 1300 (+18)
Packages and Vulnerabilities (16 package changes and 11 vulnerability changes)
  • ➕ 2 packages added
  • ➖ 1 packages removed
  • ♾️ 13 packages changed
  • 1068 packages unchanged
  • ❗ 11 vulnerabilities added
Changes for packages of type npm (16 changes)
Package Version
backstage:latest
Version
backstage:latest
@fastify/busboy 2.1.1
♾️ @octokit/endpoint 11.0.0 9.0.6
critical: 0 high: 0 medium: 1 low: 0
Added vulnerabilities (1):
  • medium : CVE--2025--25285
♾️ @octokit/openapi-types 25.1.0 24.2.0
♾️ @octokit/plugin-paginate-rest 13.1.1 9.2.2
♾️ @octokit/request 10.0.3 8.4.1
♾️ @octokit/request-error 7.0.0 5.1.1
critical: 0 high: 0 medium: 1 low: 0
Added vulnerabilities (1):
  • medium : CVE--2025--25289
@octokit/tsconfig 1.0.2
fast-content-type-parse 3.0.0
♾️ fast-xml-parser 5.3.4 5.3.6
♾️ form-data 4.0.4 4.0.5
♾️ mkdirp 0.5.6 1.0.4
♾️ on-headers 1.1.0 1.0.2
critical: 0 high: 0 medium: 0 low: 1
Added vulnerabilities (1):
  • low : CVE--2025--7339
♾️ qs 6.14.2 6.15.0
♾️ strnum 2.1.1 2.1.2
♾️ undici 7.19.2 7.22.0
♾️ universal-user-agent 7.0.3 6.0.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant