Skip to content

Create dependabot.yml - #105

Closed
guibranco wants to merge 3 commits into
mainfrom
guibranco-patch-2
Closed

Create dependabot.yml#105
guibranco wants to merge 3 commits into
mainfrom
guibranco-patch-2

Conversation

@guibranco

@guibranco guibranco commented May 1, 2026

Copy link
Copy Markdown
Owner

📑 Description

✅ Checks

  • My pull request adheres to the code style of this project
  • My code requires changes to the documentation
  • I have updated the documentation as required
  • All the tests have passed

☢️ Does this introduce a breaking change?

  • Yes
  • No

Summary by CodeRabbit

  • Chores
    • Configured automated weekly dependency and CI workflow update checks with grouped, labeled, and capped update pull requests and assigned reviewers.
    • Updated multiple runtime and development dependencies and tooling to newer versions to keep the project current and secure.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @guibranco! 👋

Your private repo does not have access to Sourcery.

Please upgrade to continue using Sourcery ✨

@coderabbitai

coderabbitai Bot commented May 1, 2026

Copy link
Copy Markdown
ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: 9f76ebe4-3b6a-48fc-8f33-8f49ab5124bc

📥 Commits

Reviewing files that changed from the base of the PR and between 2653152 and b0a03a2.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • package.json

Walkthrough

Adds a Dependabot configuration for weekly npm and GitHub Actions updates and updates dependency version ranges in package.json for runtime and dev tooling packages. No exported/public API changes.

Changes

Cohort / File(s) Summary
Dependabot Configuration
\.github/dependabot.yml
Adds Dependabot config: weekly schedule for npm and github-actions, limits open PRs to 50, assigns and requests review from guibranco, applies labels, and groups updates by package families (Vite, React, ESLint/tooling, TypeScript, i18n, Tailwind/PostCSS).
Package Manifest
package.json
Bumps multiple runtime and dev dependency version ranges (e.g., React, React DOM, Radix icons, lucide-react, tailwind-related, ESLint and plugins, TypeScript, PostCSS, Vite plugin). No code or exported API changes—only dependency/version updates.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 I hopped through package trees tonight,
Fresh versions gleam beneath the moon,
Dependabot hums, grouping them tight,
I nibble updates — voila, new tune! ✨


Note

🎁 Summarized by CodeRabbit Free

Your organization is on the Free plan. CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please upgrade your subscription to CodeRabbit Pro by visiting https://app.coderabbit.ai/login.

Review rate limit: 1/3 review remaining, refill in 38 minutes and 4 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@penify-dev

penify-dev Bot commented May 1, 2026

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@guibranco
guibranco enabled auto-merge (squash) May 1, 2026 15:18
@gstraccini gstraccini Bot added the ☑️ auto-merge Automatic merging of pull requests (gstraccini-bot) label May 1, 2026
@guibranco

Copy link
Copy Markdown
Owner Author

@gstraccini npm check updates

@gstraccini

gstraccini Bot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Running the command npm-check-updates to update dependencies via NPM! 🏗️

@gstraccini

gstraccini Bot commented May 1, 2026

Copy link
Copy Markdown
Contributor

NPM check updates result:

Upgrading /home/runner/work/gstraccini-bot-workflows/gstraccini-bot-workflows/package.json


 @eslint/js                       ^9.39.2  →   ^10.0.1
 @radix-ui/react-icons             ^1.3.0  →    ^1.3.2
 @types/node                     ^20.19.9  →   ^25.6.0
 @types/react                    ^18.3.23  →  ^19.2.14
 @types/react-dom                 ^18.3.7  →   ^19.2.3
 @vitejs/plugin-react              ^4.7.0  →    ^6.0.1
 class-variance-authority          ^0.7.0  →    ^0.7.1
 clsx                              ^2.1.0  →    ^2.1.1
 eslint                           ^9.39.2  →   ^10.2.1
 eslint-plugin-react-hooks    ^5.1.0-rc.0  →    ^7.1.1
 eslint-plugin-react-refresh      ^0.4.26  →    ^0.5.2
 globals                         ^15.15.0  →   ^17.5.0
 lucide-react                    ^0.344.0  →   ^1.14.0
 postcss                          ^8.5.12  →   ^8.5.13
 react                            ^18.3.1  →   ^19.2.5
 react-dom                        ^18.3.1  →   ^19.2.5
 tailwind-merge                    ^2.2.1  →    ^3.5.0
 tailwindcss                      ^3.4.18  →    ^4.2.4
 typescript                        ^5.9.3  →    ^6.0.3

Run npm install to install new versions.

added 209 packages, and audited 210 packages in 14s

46 packages are looking for funding
  run `npm fund` for details

found 0 vulnerabilities

added 2 packages, and audited 212 packages in 958ms

47 packages are looking for funding
  run `npm fund` for details

found 0 vulnerabilities

@socket-security

Copy link
Copy Markdown

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Medium
Low adoption: npm @humanfs/types

Location: Package overview

From: package-lock.jsonnpm/eslint@10.2.1npm/@humanfs/types@0.15.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@humanfs/types@0.15.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm @babel/core is 100.0% likely to have a medium risk anomaly

Notes: The examined code is a standard, benign helper for constructing and wrapping configuration items from descriptors within Babel’s tooling. There is no evidence of data leakage, exfiltration, backdoors, or other malicious activity in this fragment. The combination of immutability, brand-based identity, and non-enumerable descriptor storage indicates a well-scoped internal utility rather than anything suspicious.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/eslint-plugin-react-hooks@7.1.1npm/@babel/core@7.29.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/core@7.29.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Embedded URLs or IPs: npm @babel/core

URLs: http://babeljs.io/docs/plugins/external-helpers/, http://babeljs.io/docs/plugins/transform-react-jsx/, http://babeljs.io/docs/plugins/#modules, http://babeljs.io/docs/plugins/preset-react/, http://babeljs.io/docs/plugins/#presets, https://babeljs.io/docs/en/babel-core/#options, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-async-do-expressions, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-decimal, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-decorators, https://github.com/babel/babel/tree/main/packages/babel-plugin-proposal-decorators, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-do-expressions, https://github.com/babel/babel/tree/main/packages/babel-plugin-proposal-do-expressions, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-export-default-from, https://github.com/babel/babel/tree/main/packages/babel-plugin-proposal-export-default-from, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-flow, https://github.com/babel/babel/tree/main/packages/babel-preset-flow, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-function-bind, https://github.com/babel/babel/tree/main/packages/babel-plugin-proposal-function-bind, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-function-sent, https://github.com/babel/babel/tree/main/packages/babel-plugin-proposal-function-sent, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-jsx, https://github.com/babel/babel/tree/main/packages/babel-preset-react, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-pipeline-operator, https://github.com/babel/babel/tree/main/packages/babel-plugin-proposal-pipeline-operator, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-record-and-tuple, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-throw-expressions, https://github.com/babel/babel/tree/main/packages/babel-plugin-proposal-throw-expressions, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-typescript, https://github.com/babel/babel/tree/main/packages/babel-preset-typescript, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-async-generators, https://github.com/babel/babel/tree/main/packages/babel-plugin-transform-async-generator-functions, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-class-properties, https://github.com/babel/babel/tree/main/packages/babel-plugin-transform-class-properties, https://github.com/babel/babel/tree/main/packages/babel-plugin-transform-private-methods, https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-syntax-class-static-block, https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-class-static-block, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-dynamic-import, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-export-namespace-from, https://github.com/babel/babel/tree/main/packages/babel-plugin-transform-export-namespace-from, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-import-assertions, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-import-attributes, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-import-meta, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-logical-assignment-operators, https://github.com/babel/babel/tree/main/packages/babel-plugin-transform-logical-assignment-operators, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-module-string-names, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-numeric-separator, https://github.com/babel/babel/tree/main/packages/babel-plugin-transform-numeric-separator, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-nullish-coalescing-operator, https://github.com/babel/babel/tree/main/packages/babel-plugin-transform-nullish-coalescing-opearator, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-object-rest-spread, https://github.com/babel/babel/tree/main/packages/babel-plugin-transform-object-rest-spread, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-optional-catch-binding, https://github.com/babel/babel/tree/main/packages/babel-plugin-transform-optional-catch-binding, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-optional-chaining, https://github.com/babel/babel/tree/main/packages/babel-plugin-transform-optional-chaining, https://github.com/babel/babel/tree/main/packages/babel-plugin-syntax-private-property-in-object, https://github.com/babel/babel/tree/main/packages/babel-plugin-transform-private-property-in-object, https://github.com/babel/babel/blob/main/packages/babel-plugin-syntax-unicode-sets-regex/README.md, https://github.com/babel/babel/blob/main/packages/babel-plugin-proposalunicode-sets-regex/README.md, https://babeljs.io/docs/en/options#filename

Location: Package overview

From: package-lock.jsonnpm/eslint-plugin-react-hooks@7.1.1npm/@babel/core@7.29.0

ℹ Read more on: This package | This alert | What are URL strings?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Review all remote URLs to ensure they are intentional, pointing to trusted sources, and not being used for data exfiltration or loading untrusted code at runtime.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/core@7.29.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm @babel/helper-module-imports is 100.0% likely to have a medium risk anomaly

Notes: The analyzed code is a Babel AST helper (ImportBuilder) used to construct import statements and interop-wrapped imports. It contains no indicators of malicious behavior, data exfiltration, backdoors, or runtime abuses. It operates within a compiler/transpiler context to produce code, not to execute arbitrary user data. Therefore, the code itself does not present security risks or malware indicators under normal usage. This is benign library behavior intended for code transformation.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/eslint-plugin-react-hooks@7.1.1npm/@babel/helper-module-imports@7.28.6

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helper-module-imports@7.28.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm @babel/helper-module-transforms is 100.0% likely to have a medium risk anomaly

Notes: The code is a legitimate, static-code transformation utility used in Babel to ensure proper behavior of ES module bindings after transforms. There is no evidence of malicious behavior, data leakage, or external communications within this fragment. It operates purely on AST-level transformations consistent with module import/export handling.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/eslint-plugin-react-hooks@7.1.1npm/@babel/helper-module-transforms@7.28.6

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helper-module-transforms@7.28.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm @babel/helpers is 100.0% likely to have a medium risk anomaly

Notes: The analyzed fragment is a conventional Babel/TypeScript-style decorators runtime (applyDecs) responsible for applying decorators to class members and managing metadata and initializers. There is no evidence of malware, backdoors, or external data leakage within this module. While complex, the code behaves as a metadata-driven decorator processor and should be considered low risk when used as intended. Downstream risks depend on the decorators provided by consumers, not this utility itself.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/eslint-plugin-react-hooks@7.1.1npm/@babel/helpers@7.29.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helpers@7.29.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm @babel/helpers is 100.0% likely to have a medium risk anomaly

Notes: The code fragment is a standard Babel decorator runtime helper (applyDecs2203). Its security posture hinges on the trustworthiness of the supplied decorators. If decorators are from untrusted sources, they can execute arbitrary code during decoration or initialization. The library itself does not exhibit malicious behavior, but this pattern introduces a high-risk surface via external inputs. Recommended mitigations include validating decorator outputs, enforcing sandboxing or runner boundaries for decorators, and auditing decorator sources in the application.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/eslint-plugin-react-hooks@7.1.1npm/@babel/helpers@7.29.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helpers@7.29.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Embedded URLs or IPs: npm @eslint/config-array

URLs: https://facelessuser.github.io/wcmatch/glob/#posix-character-classes, https://www.linuxjournal.com/content/bash-extended-globbing., https://www.linuxjournal.com/content/globstar-new-bash-globbing-option., https://deno.land/std/path/mod.ts, https://deno.land/std/path/mod.ts?a=b, https://deno.land/std/path/mod.ts#header, https://deno.land/std/path, https://deno.land, https://deno.land/std/assert/mod.ts, https://deno.land/std/async/retry.ts

Location: Package overview

From: package-lock.jsonnpm/eslint@10.2.1npm/@eslint/config-array@0.23.5

ℹ Read more on: This package | This alert | What are URL strings?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Review all remote URLs to ensure they are intentional, pointing to trusted sources, and not being used for data exfiltration or loading untrusted code at runtime.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@eslint/config-array@0.23.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Embedded URLs or IPs: npm @floating-ui/dom

URLs: https://developer.mozilla.org/en-US/docs/Web/CSS/Containing_block#identifying_the_containing_block, https://floating-ui.com/docs/autoUpdate, https://github.com/floating-ui/floating-ui/issues/1740, https://github.com/floating-ui/floating-ui/issues/2317, https://drafts.csswg.org/css-transforms-2/#individual-transforms, https://samthor.au/2021/observing-dom/

Location: Package overview

From: package-lock.jsonnpm/@radix-ui/react-dropdown-menu@2.1.16npm/@floating-ui/dom@1.7.6

ℹ Read more on: This package | This alert | What are URL strings?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Review all remote URLs to ensure they are intentional, pointing to trusted sources, and not being used for data exfiltration or loading untrusted code at runtime.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@floating-ui/dom@1.7.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Embedded URLs or IPs: npm @types/node

URLs: ws://127.0.0.1:9229/166e272e-7a30-4d09-97ce-f1c012b43c34, https://nodejs.org/en/docs/inspector, app.js.map, https://nodejs.org/docs/latest-v25.x/api/stream.html#streamcomposestreams, readable.map, 4.4.4.4, 4.4.4.4:1053, nodejs.org, example.com, https://nodejs.org/docs/latest-v20.x/api/errors.html#class-error, https://nodejs.org/docs/latest-v20.x/api/dns.html#error-codes, https://nodejs.org/docs/latest-v20.x/api/dns.html#dnspromiseslookuphostname-options, https://tools.ietf.org/html/rfc5952#section-6, https://man7.org/linux/man-pages/man5/resolv.conf.5.html, https://nodejs.org/docs/latest-v20.x/api/dns.html#dnspromisessetdefaultresultorderorder, https://nodejs.org/docs/latest-v20.x/api/cli.html#--dns-result-orderorder, https://nodejs.org/docs/latest-v20.x/api/worker_threads.html, example.org, 0.0.0.0, 224.0.0.114, 127.0.0.1, https://en.wikipedia.org/wiki/IPv6_address#Scoped_literal_IPv6_addresses, https://tools.ietf.org/html/rfc4007, 10.0.0.2, https://www.openssl.org/docs/man1.1.1/man3/SSL_CIPHER_get_name.html, https://tools.ietf.org/html/rfc5929, https://www.openssl.org/docs/man1.1.1/man3/SSL_export_keying_material.html, https://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml#exporter-labels, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Error, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Data_structures#Undefined_type, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44531, options.ca, https://hg.mozilla.org/mozilla-central/raw-file/tip/security/nss/lib/ckfw/builtins/certdata.txt, https://nodejs.org/docs/latest-v25.x/api/errors.html#class-error, https://nodejs.org/docs/latest-v25.x/api/util.html#utilpromisifyoriginal, https://tools.ietf.org/html/rfc8482, https://nodejs.org/docs/latest-v25.x/api/dns.html#error-codes, https://nodejs.org/docs/latest-v25.x/api/dns.html#dnspromiseslookuphostname-options, https://datatracker.ietf.org/doc/html/rfc5952#section-6, https://nodejs.org/docs/latest-v25.x/api/cli.html#--dns-result-orderorder, https://nodejs.org/docs/latest-v25.x/api/worker_threads.html, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Operators/Equality, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Operators/Inequality, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Object/is, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Classes, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Guide/Regular_Expressions, https://nodejs.org/docs/latest-v25.x/api/errors.html#err_invalid_return_value, sqlTagStore.run, sql.run, https://www.sqlite.org/c3ref/changes.html, https://nodejs.org/docs/latest-v25.x/api/child_process.html#optionsstdio, https://man7.org/linux/man-pages/man2/setuid.2.html, https://man7.org/linux/man-pages/man2/setgid.2.html, http://man7.org/linux/man-pages/man2/fdatasync.2.html, http://man7.org/linux/man-pages/man2/fsync.2.html, https://tc39.github.io/ecma262/#sec-asynciterable-interface, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Iteration_protocols#The_iterable_protocol, https://developer.mozilla.org/en-US/docs/Web/API/ArrayBufferView, http://man7.org/linux/man-pages/man2/open.2.html, https://docs.microsoft.com/en-us/windows/desktop/FileIO/naming-a-file, https://docs.microsoft.com/en-us/windows/desktop/FileIO/using-streams, http://man7.org/linux/man-pages/man2/readlink.2.html, http://man7.org/linux/man-pages/man2/lstat.2.html, http://man7.org/linux/man-pages/man2/link.2.html, http://man7.org/linux/man-pages/man2/unlink.2.html, https://github.com/mdn/content/pull/38027, http://man7.org/linux/man-pages/man3/opendir.3.html, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/TypedArray/subarray, 192.168.1.1, 74.125.127.100, 123.123.123.123, 10.0.0.1, 10.0.0.10, 10.0.0.3, 222.111.111.222, 192.168.1.0/24, 10.0.0.5, 127.000.000.001, 127.0.0.1/24, https://docs.libuv.org/en/v1.x/misc.html#c.uv_available_parallelism, https://linux.die.net/man/3/uname, https://en.wikipedia.org/wiki/Uname#Examples, https://nodejs.org/docs/latest-v25.x/api/errors.html#class-systemerror, https://nodejs.org/docs/latest-v25.x/api/process.html#processarch, https://github.com/nodejs/node/blob/HEAD/BUILDING.md#androidandroid-based-devices-eg-firefox-os, https://nodejs.org/docs/latest-v25.x/api/async_hooks.html#promise-execution-tracking, https://nodejs.org/docs/latest-v25.x/api/async_hooks.html#hook-callbacks, encrypted.google.com, github.com, https://encrypted.google.com/, https://www.w3.org/TR/html52/changes.html#features-removed, https://nodejs.org/api/buffer.html#buffer_buffers_and_character_encodings, https://nodejs.org/docs/latest-v25.x/api/crypto.html#asymmetric-key-types, https://tools.ietf.org/html/rfc7517, https://www.rfc-editor.org/rfc/rfc5208.txt, https://www.rfc-editor.org/rfc/rfc1421.txt, https://en.wikipedia.org/wiki/Timing_attack, https://en.wikipedia.org/wiki/Initialization_vector, https://www.openssl.org/docs/man3.0/man3/DH_generate_key.html, https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-132.pdf, https://en.wikipedia.org/wiki/Scrypt, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/ArrayBuffer, https://www.rfc-editor.org/rfc/rfc4122.txt, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44532, https://www.rfc-editor.org/rfc/rfc2818.txt, https://www.rfc-editor.org/rfc/rfc5280.txt, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/BigInt, https://www.rfc-editor.org/rfc/rfc9106.html, https://nodejs.org/docs/latest-v25.x/api/crypto.html#using-strings-as-inputs-to-cryptographic-apis, xn--maana-pta.com, ana.com, xn----dqo34k.com, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/String/length, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/DataView, https://developer.mozilla.org/en-US/docs/Web/JavaScript/-, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/JSON/stringify, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/TypedArray/set, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Uint8Array, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/String/indexOf, https://nodejs.org/docs/latest-v25.x/api/module.html#module-compile-cache, options.directory, module.id, IO.read, https://chromedevtools.github.io/devtools-protocol/v8/, subprocess.channel, http://man7.org/linux/man-pages/man7/signal.7.html, http://man7.org/linux/man-pages/man2/kill.2.html, https://en.wikipedia.org/wiki/List_of_command-line_interpreters, test.sh, http://man7.org/linux/man-pages/man3/exec.3.html, http://man7.org/linux/man-pages/man2/fork.2.html, https://nodejs.org/docs/latest-v25.x/api/modules.md#loading-ecmascript-modules-using-require, fs.read, process.report.directory, https://nodejs.org/docs/latest-v25.x/api/cli.html#program-entry-point, https://nodejs.org/docs/latest-v25.x/api/os.html#dlopen-constants, http://man7.org/linux/man-pages/man7/environ.7.html, process.pid, https://docs.libuv.org/en/v1.x/misc.html#c.uv_get_constrained_memory, https://nodejs.org/docs/latest-v25.x/api/process.html#processavailablememory, https://nodejs.org/api/cli.html#--permission, https://nodejs.org/api/permissions.html#permission-model, https://nodejs.org/download/release/v18.12.0/node-v18.12.0.tar.gz, https://nodejs.org/download/release/v18.12.0/node-v18.12.0-headers.tar.gz, https://nodejs.org/download/release/v18.12.0/win-x64/node.lib, https://nodejs.org/docs/latest-v25.x/api/report.html, process.report, https://nodejs.org/dist/latest-v25.x/docs/api/repl.html#repl_customizing_repl_output, https://nodejs.org/dist/latest-v25.x/docs/api/readline.html#readline_use_of_the_completer_function, https://nodejs.org/dist/latest-v25.x/docs/api/repl.html#repl_class_replserver, https://nodejs.org/dist/latest-v25.x/docs/api/repl.html#repl_commands_and_special_keys, https://nodejs.org/dist/latest-v25.x/docs/api/repl.html#repl_assignment_of_the_underscore_variable, https://nodejs.org/docs/latest-v25.x/api/async_context.html, https://nodejs.org/docs/latest-v25.x/api/test.html#test-runner-execution-model, https://nodejs.org/docs/latest-v25.x/api/cli.html#--test-update-snapshots, http://man7.org/linux/man-pages/man3/readdir.3.html, http://man7.org/linux/man-pages/man2/mkdir.2.html, http://man7.org/linux/man-pages/man2/pwrite.2.html, fs.watch, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Number/MAX_SAFE_INTEGER, 127.0.0.1:8000, process.env.HOST, req.headers.host, https://nodejs.org/docs/latest-v25.x/api/http.html#built-in-proxy-support, https://nodejs.org/docs/latest-v25.x/api/net.html#socketconnectoptions-connectlistener, http://example.org:8000, https://example.org:80, https://example.org/foo/bar, https://example.org, http2stream.id, https://example.com, request.stream, http://example.com, http://example.com/status?name=ryan, https://nodejs.org/docs/latest-v25.x/api/errors.html#class-typeerror, response.stream, https://tools.ietf.org/html/rfc7540, https://http2.github.io/faq/#does-http2-require-encryption, https://chromedevtools.github.io/devtools-protocol/1-3/Runtime/#type-ScriptId, https://nodejs.org/docs/latest-v25.x/api/util.html#modifiers, https://github.com/microsoft/TypeScript/issues/12936, https://nodejs.org/docs/latest-v25.x/api/vm.html#support-of-dynamic-import-in-compilation-apis, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval, https://es5.github.io/#x10.4.2, https://tc39.es/ecma262/#sec-abstract-module-records, https://tc39.es/ecma262/#sec-cyclic-module-records, https://tc39.es/ecma262/#sec-getmodulenamespace, https://tc39.es/ecma262/#sec-moduleevaluation, https://tc39.es/ecma262/#sec-smr-Evaluate, https://heycam.github.io/webidl/#synthetic-module-records, https://developer.mozilla.org/en-US/docs/Web/API/Web_Workers_API, https://v8docs.nodesource.com/node-13.2/d5/dda/classv8_1_1_isolate.html#a6079122af17612ef54ef3348ce170866, https://nodejs.org/docs/latest-v25.x/api/cli.html#--heapsnapshot-near-heap-limitmax_count, https://nodejs.org/docs/latest-v25.x/api/worker_threads.html#worker-threads, https://example.com/some/path?page=1&#x26, urlObject.host, urlObject.search, http://example.com/, http://example.com/one, http://example.com/two, https://tools.ietf.org/html/rfc5891#section-4.4, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Data_structures#String_type, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Data_structures#Number_type, https://developer.mozilla.org/en-US/docs/Web/JavaScript/Data_structures#Boolean_type

Location: Package overview

From: package-lock.jsonnpm/@types/node@25.6.0

ℹ Read more on: This package | This alert | What are URL strings?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Review all remote URLs to ensure they are intentional, pointing to trusted sources, and not being used for data exfiltration or loading untrusted code at runtime.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@types/node@25.6.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Embedded URLs or IPs: npm @types/react-dom

URLs: https://react.dev/reference/react-dom/server/resumeToPipeableStream

Location: Package overview

From: package-lock.jsonnpm/@types/react-dom@19.2.3

ℹ Read more on: This package | This alert | What are URL strings?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Review all remote URLs to ensure they are intentional, pointing to trusted sources, and not being used for data exfiltration or loading untrusted code at runtime.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@types/react-dom@19.2.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Embedded URLs or IPs: npm @types/react

URLs: https://developer.mozilla.org/en-US/docs/Web/API/View_Transition_API, https://react.dev/reference/react-dom/components/common#ref-callback, https://react.dev/reference/react/Component#static-contexttype, https://react.dev/reference/react/Component#context, https://www.typescriptlang.org/docs/handbook/2/conditional-types.html#distributive-conditional-types, https://github.com/microsoft/TypeScript/issues/28339, https://react.dev/reference/react/useContext, https://react.dev/reference/react/useState, https://react.dev/reference/react/useReducer, https://react.dev/reference/react/useRef, https://react.dev/reference/react/useLayoutEffect, https://react.dev/reference/react/useEffect, https://react.dev/reference/react/useEffectEvent, https://react.dev/reference/react/useImperativeHandle, https://react.dev/reference/react/useDebugValue, https://github.com/react/react/pull/21913, https://github.com/reactwg/react-18/discussions/86, https://react.dev/reference/react/Activity, https://react.dev/reference/react/captureOwnerStack, https://github.com/DefinitelyTyped/DefinitelyTyped/issues/11508#issuecomment-256045682, https://github.com/frenic/csstype#what-should-i-do-when-i-get-type-errors, https://www.w3.org/TR/wai-aria-1.1/

Location: Package overview

From: package-lock.jsonnpm/@types/react@19.2.14

ℹ Read more on: This package | This alert | What are URL strings?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Review all remote URLs to ensure they are intentional, pointing to trusted sources, and not being used for data exfiltration or loading untrusted code at runtime.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@types/react@19.2.14. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Embedded URLs or IPs: npm @vitejs/plugin-react

URLs: https://github.com/react/react/issues/20417., https://github.com/vitejs/vite-plugin-react/tree/main/packages/plugin-react

Location: Package overview

From: package-lock.jsonnpm/@vitejs/plugin-react@6.0.1

ℹ Read more on: This package | This alert | What are URL strings?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Review all remote URLs to ensure they are intentional, pointing to trusted sources, and not being used for data exfiltration or loading untrusted code at runtime.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@vitejs/plugin-react@6.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm ajv is 100.0% likely to have a medium risk anomaly

Notes: The code represents a conventional, non-obfuscated part of AJV’s custom keyword support. No direct malicious actions are evident within this module. Security concerns mainly arise from the broader supply chain: the external rule implementation (dotjs/custom), the definition schema, and any user-supplied keyword definitions. The dynamic compilation path (compile(metaSchema, true)) should be exercised with trusted inputs. Recommended follow-up: review the contents of the external modules and monitor the inputs supplied to addKeyword/definitionSchema to ensure no unsafe behavior is introduced during validation or data handling.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/eslint@10.2.1npm/ajv@6.15.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ajv@6.15.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm ajv is 100.0% likely to have a medium risk anomaly

Notes: The code augments a meta-schema to permit remote dereferencing of keyword schemas via a hardcoded data.json resource. This introduces network dependency and potential changes to validation semantics at runtime. While not inherently malicious, the remote reference constitutes a notable security and reliability risk that should be mitigated with local fallbacks, input validation, and explicit remote-resource governance.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/eslint@10.2.1npm/ajv@6.15.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ajv@6.15.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm ajv is 100.0% likely to have a medium risk anomaly

Notes: The code is a straightforward build script to bundle and minify a specified package using Browserify and UglifyJS. The primary security concern is potential path manipulation: json.main is used to form a require path without validating that it stays within the target package directory. If a malicious or misconfigured package.json includes an absolute path or traversal outside the package, the script could bundle unintended files. Otherwise, the script does not perform network access, data exfiltration, or backdoor actions, and there is no hard-coded secrets or dynamic code execution beyond standard bundling/minification.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/eslint@10.2.1npm/ajv@6.15.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ajv@6.15.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Embedded URLs or IPs: npm ajv

URLs: https://raw.githubusercontent.com/ajv-validator/ajv/master/lib/refs/data.json#, http://json-schema.org/draft-07/schema, schema.id, http://json-schema.org/schema, https://gist.github.com/dperini/729294, https://mathiasbynens.be/demo/url-regex, https://github.com/eslint/eslint/issues/7983., http://tools.ietf.org/html/rfc3339#section-5.6, https://github.com/mafintosh/is-my-json-valid/blob/master/formats.js, http://stackoverflow.com/questions/201323/using-a-regular-expression-to-validate-an-email-address#answer-8829363, http://www.w3.org/TR/html5/forms.html#valid-e-mail-address, https://www.safaribooksonline.com/library/view/regular-expressions-cookbook/9780596802837/ch07s16.html, http://stackoverflow.com/questions/53497/regular-expression-that-matches-valid-ipv6-addresses, http://tools.ietf.org/html/rfc4122, https://tools.ietf.org/html/rfc6901, https://tools.ietf.org/html/rfc3986#appendix-A, http://tools.ietf.org/html/draft-luff-relative-json-pointer-00, https://tools.ietf.org/html/rfc3339#appendix-C, http://jmrware.com/articles/2009/uri_regexp/URI_regex.html, min.js.map, https://github.com/ajv-validator/ajv/blob/master/lib/definition_schema.js, http://json-schema.org/draft-07/schema#, https://mathiasbynens.be/notes/javascript-encoding, https://github.com/bestiejs/punycode.js, https://tools.ietf.org/html/rfc3492#section-3.4, gary.court@gmail.com, https://github.com/epoberezkin/fast-json-stable-stringify

Location: Package overview

From: package-lock.jsonnpm/eslint@10.2.1npm/ajv@6.15.0

ℹ Read more on: This package | This alert | What are URL strings?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Review all remote URLs to ensure they are intentional, pointing to trusted sources, and not being used for data exfiltration or loading untrusted code at runtime.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ajv@6.15.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

See 14 more rows in the dashboard

View full report

@guibranco guibranco closed this May 7, 2026
auto-merge was automatically disabled May 7, 2026 16:57

Pull request was closed

@guibranco
guibranco deleted the guibranco-patch-2 branch May 7, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

☑️ auto-merge Automatic merging of pull requests (gstraccini-bot)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant