Skip to content

Conversation

@prashantasdeveloper
Copy link
Contributor

JIRA Link

DA-1546

Changelog / Description

Bump dependencies to resolve socket warnings

Checklist -

  • New Feature ?
  • Updated swagger annotation (if API structure is changed) ?
  • Unit Test (if possible) ?
  • Updated the Readme.md (if required) ?

@socket-security
Copy link

socket-security bot commented Oct 6, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​nestjs/​schematics@​10.0.2 ⏵ 11.0.910010084 +192 -10
Updated@​types/​axios@​0.14.0 ⏵ 0.14.4100 +110038 +177100
Updated@​types/​cron@​1.7.3 ⏵ 2.4.310010039 -3280 +2100
Updated@​types/​json-stable-stringify@​1.0.34 ⏵ 1.2.010010039 -4778100
Addedjson-stable-stringify@​1.3.06710010054100
Updated@​types/​jest-when@​3.5.2 ⏵ 3.5.510010068 -178100
Added@​types/​express@​5.0.31001007192100
Updated@​types/​supertest@​2.0.12 ⏵ 6.0.310010071 -2479100
Added@​polymeshassociation/​signing-manager-types@​3.4.2751007281100
Updated@​polymeshassociation/​hashicorp-vault-signing-manager@​3.4.0 ⏵ 3.5.07210076 +177 -1100
Updated@​commitlint/​cli@​17.7.1 ⏵ 20.1.099 +110073 -189 -1100
Updated@​types/​passport@​1.0.12 ⏵ 1.0.17100 +11007578100
Updated@​polymeshassociation/​local-signing-manager@​3.3.0 ⏵ 3.5.276 +510085 +1181 +3100
Updatedswagger-ui-express@​5.0.0 ⏵ 5.0.110010010078100
Updatedjoi@​17.4.0 ⏵ 18.0.110010079 +185100
Updatedts-node@​10.9.1 ⏵ 10.9.297 +110010080100
Updated@​nestjs/​typeorm@​10.0.2 ⏵ 11.0.099 +110086 +181100
Updated@​nestjs/​config@​3.2.2 ⏵ 4.0.299 +11008682100
Addedrxjs@​7.8.29910010082100
Updated@​nestjs/​axios@​3.0.2 ⏵ 4.0.11001008583100
Updatedts-loader@​9.4.4 ⏵ 9.5.49910010083100
Updated@​nestjs/​passport@​10.0.3 ⏵ 11.0.510010085 +184100
Updatedjest-when@​3.6.0 ⏵ 3.7.0100 +1100100 +184 +7100
Updated@​nestjs/​cli@​10.1.17 ⏵ 11.0.1098 +11008491 -1100
Updatedpg@​8.11.5 ⏵ 8.16.399 +110099 +285100
Updatedpath-to-regexp@​0.1.7 ⏵ 8.3.0100100 +40100 +2485100
Updated@​nestjs/​schedule@​4.0.2 ⏵ 6.0.1100 +11008685 -2100
Updated@​semantic-release/​exec@​6.0.3 ⏵ 7.1.0100 +110010086100
Updatedsupertest@​6.1.3 ⏵ 7.1.499100100 +187 +1100
Updated@​nestjs/​swagger@​7.3.1 ⏵ 11.2.19910087 -892 +4100
Updated@​commitlint/​config-conventional@​17.7.0 ⏵ 20.0.010010010088 -3100
See 8 more rows in the dashboard

View full report

@socket-security
Copy link

socket-security bot commented Oct 6, 2025

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm npm is 94.0% likely obfuscated

Confidence: 0.94

Location: Package overview

From: ?npm/@semantic-release/[email protected]npm/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@prashantasdeveloper prashantasdeveloper marked this pull request as ready for review October 27, 2025 13:20
@prashantasdeveloper prashantasdeveloper changed the title chore: 🤖 bump dependencies chore: 🤖 bump NestJS and other deps Oct 27, 2025
@sonarqubecloud
Copy link

sonarqubecloud bot commented Nov 3, 2025

@prashantasdeveloper
Copy link
Contributor Author

/fast-forward

@polymath-eric polymath-eric merged commit 2d62064 into alpha Nov 3, 2025
10 checks passed
@polymath-eric polymath-eric deleted the fix/socket-warning branch November 3, 2025 11:46
@polymesh-bot
Copy link
Contributor

🎉 This PR is included in version 8.0.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants