trezor-suite icon indicating copy to clipboard operation
trezor-suite copied to clipboard

chore(suite): upgrade lib: yup

Open peter-sanderson opened this issue 10 months ago • 2 comments

Description

Related Issue

Resolve https://github.com/trezor/trezor-suite/issues/7611

Screenshots:

peter-sanderson avatar May 03 '24 12:05 peter-sanderson

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSource
Uses eval npm/[email protected]
Shell access npm/[email protected]
Filesystem access npm/[email protected]
Filesystem access npm/@istanbuljs/[email protected]
Filesystem access npm/[email protected]
New author npm/@babel/[email protected]
New author npm/@babel/[email protected]
New author npm/@babel/[email protected]
Filesystem access npm/[email protected]
Filesystem access npm/[email protected]
Network access npm/[email protected]
Filesystem access npm/[email protected]
Network access npm/[email protected]
Network access npm/[email protected]
Filesystem access npm/@nodelib/[email protected]
Filesystem access npm/@nodelib/[email protected]
Filesystem access npm/[email protected]
Filesystem access npm/@kwsites/[email protected]
Network access npm/@protobufjs/[email protected]
Install scripts npm/[email protected]
  • Install script: postinstall
  • Source: node scripts/postinstall
Filesystem access npm/[email protected]
Network access npm/[email protected]
Filesystem access npm/@cspotcode/[email protected]
Shell access npm/@aw-web-design/[email protected]
New author npm/@expo/[email protected]
Filesystem access npm/@expo/[email protected]
Filesystem access npm/[email protected]
Filesystem access npm/[email protected]
Filesystem access npm/[email protected]
Filesystem access npm/[email protected]
Filesystem access npm/@expo/[email protected]
Shell access npm/@expo/[email protected]
New author npm/@expo/[email protected]
New author npm/@hapi/[email protected]
Filesystem access npm/@npmcli/[email protected]
Filesystem access npm/@npmcli/[email protected]
Filesystem access npm/[email protected]
Floating dependency npm/@jest/[email protected]
New author npm/@react-native/[email protected]
New author npm/@segment/[email protected]
New author npm/@sideway/[email protected]
Shell access npm/[email protected]
Network access npm/[email protected]
Filesystem access npm/[email protected]
Network access npm/[email protected]
Filesystem access npm/[email protected]
Filesystem access npm/[email protected]
Network access npm/[email protected]
Shell access npm/[email protected]
Network access npm/[email protected]
Install scripts npm/[email protected]
Network access npm/[email protected]
Network access npm/[email protected]
Network access npm/[email protected]
Network access npm/@ndelangen/[email protected]
Network access npm/@ndelangen/[email protected]
Network access npm/@ndelangen/[email protected]
Network access npm/@ndelangen/[email protected]
Network access npm/@ndelangen/[email protected]
Network access npm/@ndelangen/[email protected]
New author npm/@cypress/[email protected]
Filesystem access npm/@cypress/[email protected]

socket-security[bot] avatar May 03 '24 13:05 socket-security[bot]

I would remove yup in favor of typebox https://github.com/trezor/trezor-suite/blob/develop/packages/schema-utils/package.json#L29

mroz22 avatar May 06 '24 08:05 mroz22