make-crypto-mobile-hackathon icon indicating copy to clipboard operation
make-crypto-mobile-hackathon copied to clipboard

governcelo

Open ianmunge0 opened this issue 4 years ago • 2 comments

A mobile dApp for making Celo improvement proposals and Celo governance proposals

ianmunge0 avatar Nov 26 '21 12:11 ianmunge0

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Issue Package Version Note Source
Native code bufferutil 4.0.7
Native code keccak 3.0.3
Native code secp256k1 4.0.3
Native code utf-8-validate 5.0.10
Install scripts web3 1.10.0
  • Install script: postinstall
  • Source: echo "Web3.js 4.x alpha has been released for early testing and feedback. Checkout doc at https://docs.web3js.org/ "
Install scripts web3 1.3.6
  • Install script: postinstall
  • Source: echo "WARNING: the web3-shh and web3-bzz api will be deprecated in the next version"
Install scripts web3-bzz 1.10.0
  • Install script: postinstall
  • Source: echo "WARNING: the web3-bzz api will be deprecated in the next version"
Install scripts web3-bzz 1.3.6
  • Install script: postinstall
  • Source: echo "WARNING: the web3-bzz api will be deprecated in the next version"
Install scripts postinstall-postinstall 2.1.0
Install scripts web3-shh 1.10.0
  • Install script: postinstall
  • Source: echo "WARNING: the web3-shh api will be deprecated in the next version"
Install scripts web3-shh 1.3.6
  • Install script: postinstall
  • Source: echo "WARNING: the web3-shh api will be deprecated in the next version"
Install scripts es5-ext 0.10.62
  • Install script: postinstall
  • Source: node -e "try{require('./_postinstall')}catch(e){}" || exit 0
Protestware/Troll package es5-ext 0.10.62
  • Note: This package prints a protestware console message on install regarding Ukraine for users with Russian language locale

Next steps

What's wrong with native code?

Contains native code which could be a vector to obscure malicious code, and generally decrease the likelihood of reproducible or reliable installs.

Ensure that native code bindings are expected. Consumers may consider pure JS and functionally similar alternatives to avoid the challenges and risks associated with native code bindings.

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

What is protestware and troll packages?

This package is a joke, parody, or includes undocumented or hidden behavior unrelated to its primary function.

Consider that consuming this package my come along with functionality unrelated to its primary purpose.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore [email protected] bar@* or ignore all packages with @SocketSecurity ignore-all

socket-security[bot] avatar Oct 18 '22 21:10 socket-security[bot]

New dependencies detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives Size Publisher
node-libs-react-native 1.2.1 eval, network, filesystem, shell, environment +89 5.71 MB parshap
postinstall-postinstall 2.1.0 filesystem, shell +0 2.74 kB ds300
jest-expo 48.0.2 eval, network, filesystem, shell, environment +163 20.3 MB kudochien
os-browserify 0.3.0 None +0 2.74 kB coderpuppy
react-native-snackbar-component 1.1.12 eval, network, filesystem, shell, environment +520 235 MB sidevesh
react-native-randombytes 3.6.1 filesystem, shell, environment +5 2.58 MB tenaciousmv
stream-browserify 3.0.0 environment +5 192 kB goto-bus-stop
https-browserify 1.0.0 network +0 2.79 kB feross
@walletconnect/modal-react-native 1.0.0-rc.5 eval, network, filesystem, shell, environment +549 244 MB nachosan
vm-browserify 1.1.2 None +0 15.5 kB goto-bus-stop
web3 1.10.0 eval, network, filesystem, shell, environment +328 35.5 MB jdevcs
@react-navigation/native 6.1.7 eval, network, filesystem, shell, environment +529 237 MB kacperkapusciak
expo 46.0.21 eval, network, filesystem, shell, environment +490 41.3 MB kudochien
path-browserify 1.0.1 None +0 54.3 kB goto-bus-stop
react-native-get-random-values 1.9.0 eval, network, filesystem, shell, environment +520 235 MB linusu
react-native 0.69.9 eval, network, filesystem, shell, environment +518 235 MB react-native-bot
@react-navigation/drawer 6.6.3 eval, network, filesystem, shell, environment +549 287 MB kacperkapusciak
expo-clipboard 3.1.0 eval, network, filesystem, shell, environment +491 41.5 MB brentvatne
@react-native-async-storage/async-storage 1.19.0 None +2 438 kB krizzu
@react-navigation/stack 6.3.17 eval, network, filesystem, shell, environment +544 242 MB kacperkapusciak
react 18.0.0 filesystem, environment +2 337 kB acdlite
expo-status-bar 1.4.4 None +0 45.2 kB brentvatne
react-test-renderer 18.0.0 filesystem, environment +8 2.04 MB acdlite
react-native-web 0.18.9 eval, network, filesystem, environment +21 8.75 MB necolas
react-dom 18.0.0 filesystem, environment +4 4.81 MB acdlite
expo-secure-store 11.3.0 eval, network, filesystem, shell, environment +491 41.4 MB brentvatne
expo-web-browser 12.0.0 eval, network, filesystem, shell, environment +499 41.5 MB tsapeta
react-native-background-timer 2.4.1 eval, network, filesystem, shell, environment +519 235 MB ocetnik
base-64 1.0.0 None +0 10.9 kB mathias
big-integer 1.6.51 None +0 164 kB peterolson
buffer 6.0.3 None +2 108 kB feross
@react-native-community/masked-view 0.1.11 eval, network, filesystem, shell, environment +519 235 MB naturalclar
stream-http 3.2.0 network, environment +7 218 kB jhiesey
react-native-reanimated 2.17.0 eval, network, filesystem, shell, environment +523 281 MB tomekzaw
patch-package 6.5.1 eval, filesystem, shell, environment +50 2.01 MB ds300
react-native-modal 13.0.1 eval, network, filesystem, shell, environment +521 235 MB mmazzarolo
react-native-gesture-handler 2.1.3 eval, filesystem, environment +10 4.23 MB jakub.piasecki
deprecated-react-native-prop-types 2.3.0 filesystem, environment +7 228 kB yungsters
react-native-dotenv 3.4.9 filesystem, environment +1 93 kB goatandsheep
@react-native-community/netinfo 9.4.1 eval, network, filesystem, shell, environment +519 236 MB mattoakes
axios 0.27.2 network, filesystem, environment +7 788 kB jasonsaayman
react-native-svg 13.10.0 eval, network, filesystem, shell, environment +530 240 MB wolewicki
react-native-safe-area-context 3.3.2 eval, network, filesystem, shell, environment +519 235 MB janicduplessis
react-native-paper 4.12.5 eval, network, filesystem, shell, environment +534 244 MB lukewalczak
@octokit/oauth-app 3.7.1 eval, network, filesystem, shell, environment +73 96.2 MB octokitbot
expo-updates 0.14.7 eval, network, filesystem, shell, environment +496 43.9 MB kudochien
@octokit/core 3.6.0 network +13 2.69 MB octokitbot
react-native-screens 3.14.0 eval, network, filesystem, shell, environment +521 236 MB kacperkapusciak
expo-splash-screen 0.16.2 eval, network, filesystem, shell, environment +499 43.8 MB brentvatne
@celo/contractkit 3.2.0 eval, network, filesystem, shell, environment +365 40.9 MB alecps
typescript 4.3.5 filesystem +0 60.7 MB typescript-bot

socket-security[bot] avatar Jun 18 '23 16:06 socket-security[bot]