Skip to content

Conversation

@prashantasdeveloper
Copy link
Contributor

JIRA Link

DA-1546

Changelog / Description

Bump dependencies to resolve socket warnings

Checklist -

  • New Feature ?
  • Updated swagger annotation (if API structure is changed) ?
  • Unit Test (if possible) ?
  • Updated the Readme.md (if required) ?

@socket-security
Copy link

socket-security bot commented Oct 6, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​nestjs/​schematics@​10.0.2 ⏵ 11.0.910010084 +192 -10
Updated@​types/​axios@​0.14.0 ⏵ 0.14.4100 +110038 +177100
Updated@​types/​cron@​1.7.3 ⏵ 2.4.310010039 -3280 +2100
Updated@​types/​json-stable-stringify@​1.0.34 ⏵ 1.2.010010039 -4778100
Updatedjson-stable-stringify@​1.0.2 ⏵ 1.3.06710010054 +1100
Updated@​types/​jest-when@​3.5.2 ⏵ 3.5.510010068 -178100
Updated@​types/​express@​4.17.17 ⏵ 5.0.3100 +11007181 -8100
Updated@​types/​supertest@​2.0.12 ⏵ 6.0.310010071 -2479100
Updated@​polymeshassociation/​signing-manager-types@​3.3.0 ⏵ 3.4.275 +610072 +1281 +2100
Updatedeslint-config-prettier@​9.0.0 ⏵ 9.1.2100 +110072 +187100
Updated@​polymeshassociation/​hashicorp-vault-signing-manager@​3.4.0 ⏵ 3.5.07210076 +177 -1100
Updated@​commitlint/​cli@​17.7.1 ⏵ 20.1.099 +110073 -191100
Updated@​types/​passport@​1.0.12 ⏵ 1.0.17100 +11007579100
Updated@​polymeshassociation/​local-signing-manager@​3.3.0 ⏵ 3.5.276 +510085 +1181 +3100
Updated@​polymeshassociation/​polymesh-types@​6.2.0 ⏵ 6.3.09710076 +187100
Updatedswagger-ui-express@​5.0.0 ⏵ 5.0.110010010078100
Updatedjoi@​17.4.0 ⏵ 18.0.110010079 +185100
Updated@​types/​lodash@​4.14.198 ⏵ 4.17.201001008083100
Updatedts-node@​10.9.1 ⏵ 10.9.297 +110010080100
Updated@​nestjs/​typeorm@​10.0.2 ⏵ 11.0.099 +110086 +181100
Updatedclass-validator@​0.14.0 ⏵ 0.14.2100 +1100100 +181100
Updated@​types/​node@​20.10.2 ⏵ 24.9.11001008196100
Updatedeslint-plugin-promise@​6.1.1 ⏵ 6.6.010010010081100
Updated@​nestjs/​config@​3.2.2 ⏵ 4.0.299 +11008682100
Updatedrxjs@​7.8.1 ⏵ 7.8.29910010082100
Updatedeslint-plugin-import@​2.28.1 ⏵ 2.32.09810010082100
Updatedrhea-promise@​3.0.1 ⏵ 3.0.310010010082 +1100
Updatedts-loader@​9.4.4 ⏵ 9.5.49910010083100
Updated@​nestjs/​axios@​3.0.2 ⏵ 4.0.11001008583100
Updated@​nestjs/​passport@​10.0.3 ⏵ 11.0.510010085 +184100
Updatedjest-when@​3.6.0 ⏵ 3.7.0100 +1100100 +184 +7100
See 20 more rows in the dashboard

View full report

@socket-security
Copy link

socket-security bot commented Oct 6, 2025

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
[email protected] has Obfuscated code.

Confidence: 0.94

Location: Package overview

From: ?npm/@semantic-release/[email protected]npm/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@sonarqubecloud
Copy link

sonarqubecloud bot commented Oct 27, 2025

Quality Gate Passed Quality Gate passed

Issues
0 New issues
4 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@prashantasdeveloper prashantasdeveloper marked this pull request as ready for review October 27, 2025 13:20
@prashantasdeveloper prashantasdeveloper changed the title chore: 🤖 bump dependencies chore: 🤖 bump NestJS and other deps Oct 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants