Skip to content

Update dependency @celo/contractkit to v4.1.1 - #176

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/celo-contractkit-4.x-lockfile
Open

Update dependency @celo/contractkit to v4.1.1#176
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/celo-contractkit-4.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Feb 5, 2024

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@celo/contractkit (source) 4.1.04.1.1 age confidence

Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@socket-security

socket-security Bot commented Feb 5, 2024

Copy link
Copy Markdown

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block High
es5-ext@0.10.64 is Protestware or potentially unwanted behavior.

Note: The script attempts to run a local post-install script, which could potentially contain malicious code. The error handling suggests that it is designed to fail silently, which is a common tactic in malicious scripts.

From: yarn.locknpm/es5-ext@0.10.64

ℹ Read more on: This package | This alert | What is protestware?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Consider that consuming this package may come along with functionality unrelated to its primary purpose.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es5-ext@0.10.64. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
core-js-pure@3.21.1 has Install scripts.

Install script: postinstall

Source: node -e "try{require('./postinstall')}catch(e){}"

From: yarn.locknpm/core-js-pure@3.21.1

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/core-js-pure@3.21.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
es5-ext@0.10.64 has Install scripts.

Install script: postinstall

Source: node -e "try{require('./_postinstall')}catch(e){}" || exit 0

From: yarn.locknpm/es5-ext@0.10.64

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es5-ext@0.10.64. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
ganache-core@2.13.2 has Native code.

Location: Package overview

From: yarn.locknpm/ganache-core@2.13.2

ℹ Read more on: This package | This alert | Why is native code a concern?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Verify that the inclusion of native code is expected and necessary for this package's functionality. If it is unnecessary or unexpected, consider using alternative packages without native code to mitigate potential risks.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ganache-core@2.13.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
postinstall-postinstall@2.1.0 has Install scripts.

Install script: postinstall

Source: node ./run.js

From: yarn.locknpm/postinstall-postinstall@2.1.0

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/postinstall-postinstall@2.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
web3@1.10.0 has Install scripts.

Install script: postinstall

Source: echo "Web3.js 4.x alpha has been released for early testing and feedback. Checkout doc at https://docs.web3js.org/ "

From: package.jsonnpm/web3@1.10.0

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/web3@1.10.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
open@7.4.2 is a AI-detected potential code anomaly.

Notes: The code poses security risks due to potential unauthorized code execution and obfuscated PowerShell command construction.

Confidence: 1.00

Severity: 0.60

From: yarn.locknpm/open@7.4.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/open@7.4.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
prettier@2.5.1 is a AI-detected potential code anomaly.

Notes: This file contains a legitimate bundled/minified JavaScript parser and formatter library (appears to be parts of Prettier with Meriyah parser components). The code implements standard lexical analysis, AST parsing, semver utilities, and code formatting functionality. While heavily minified and containing large Unicode/HTML entity lookup tables that may appear suspicious and may lead to debugging issues or anomalies, this is normal for parser libraries. The code performs no network requests, file system operations, dynamic code execution, or credential harvesting. The only security considerations are standard parser risks: it may echo input in error messages and will invoke user-supplied callbacks (onComment/onToken) with parsed content, which are expected behaviors for a parsing library.

Confidence: 1.00

Severity: 0.60

From: package.jsonnpm/prettier@2.5.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/prettier@2.5.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
solc@0.6.12 is a AI-detected potential code anomaly.

Notes: No clear signs of intentional malware or data-exfiltration routines in this module fragment. The main security concern is the module's ability to download arbitrary solc JavaScript binaries over HTTPS and execute them directly via require-from-string without integrity checks — this is a standard feature for on-demand compiler loading but is a supply-chain risk if the remote host is compromised or DNS/transport is attacked. Callers should only use loadRemoteVersion with trusted versions and consider additional integrity verification (checksums or signatures). User-supplied callbacks are executed and their return values are copied into WASM memory; ensure callbacks are from trusted sources. No hard-coded secrets or obfuscation detected.

Confidence: 1.00

Severity: 0.60

From: yarn.locknpm/solc@0.6.12

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/solc@0.6.12. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 3 times, most recently from df4b4d8 to ae13145 Compare February 9, 2024 19:26
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 3 times, most recently from 64828e8 to c7e7cb9 Compare February 29, 2024 10:51
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 2 times, most recently from aa2961e to 80d8ed1 Compare March 6, 2024 21:46
@socket-security

socket-security Bot commented Mar 11, 2024

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 80d8ed1 to f6958ab Compare March 18, 2024 20:54
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from f6958ab to 81f80c6 Compare May 13, 2024 13:59
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 2 times, most recently from 27ea601 to 66b9320 Compare July 24, 2024 15:52
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 66b9320 to 998bdd8 Compare November 6, 2024 11:50
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 2 times, most recently from 4289c90 to c716f68 Compare January 30, 2025 16:36
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from c716f68 to a594407 Compare February 9, 2025 15:47
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from a594407 to 9c8e7aa Compare March 3, 2025 13:22
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 9c8e7aa to d843350 Compare March 11, 2025 09:20
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from d843350 to 5a60d53 Compare April 1, 2025 08:26
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 5a60d53 to 25e10a3 Compare April 8, 2025 16:03
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 25e10a3 to dd6d411 Compare April 24, 2025 12:30
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from dd6d411 to af65a8f Compare May 19, 2025 19:05
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 2 times, most recently from 5924e71 to d5f7064 Compare June 4, 2025 07:38
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from d5f7064 to abcab29 Compare June 22, 2025 11:55
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from abcab29 to cb6fde4 Compare July 2, 2025 16:35
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from cb6fde4 to 55f8ba8 Compare August 10, 2025 15:34
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 55f8ba8 to 3a56b36 Compare August 19, 2025 11:49
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 3a56b36 to 7d40a22 Compare September 25, 2025 18:00
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 7d40a22 to d904d79 Compare October 21, 2025 18:46
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 2 times, most recently from abecc3c to acd998f Compare November 3, 2025 13:20
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from acd998f to 35f6a7a Compare November 10, 2025 22:50
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 35f6a7a to 5e1120f Compare November 18, 2025 23:41
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 2 times, most recently from 59f400f to 475fcd1 Compare December 9, 2025 14:51
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 475fcd1 to f9d056c Compare December 15, 2025 08:38
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from f9d056c to ae92c05 Compare December 31, 2025 18:31
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 2 times, most recently from 02c4e24 to c00ac2a Compare January 23, 2026 21:10
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from c00ac2a to 7dbac7f Compare February 2, 2026 16:03
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 2 times, most recently from c19a14d to 333bda4 Compare February 17, 2026 18:36
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 333bda4 to e5de884 Compare March 5, 2026 16:47
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from e5de884 to 25a1d4d Compare March 13, 2026 12:46
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 25a1d4d to 2ab41cd Compare March 27, 2026 10:50
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 2ab41cd to c1f46b6 Compare April 8, 2026 15:50
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from c1f46b6 to 0044e04 Compare April 29, 2026 17:06
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 2 times, most recently from 0d6c403 to 0660621 Compare May 18, 2026 13:49
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 0660621 to e7b227c Compare May 28, 2026 22:38
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch 2 times, most recently from 0ba30a0 to 9e3e26b Compare June 12, 2026 12:38
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 9e3e26b to 64869a1 Compare July 12, 2026 15:03
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate
renovate Bot force-pushed the renovate/celo-contractkit-4.x-lockfile branch from 64869a1 to 997c9fe Compare July 30, 2026 19:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant