chore(deps): bump the dependencies group across 1 directory with 4 updates
Bumps the dependencies group with 4 updates in the / directory: @nodesecure/js-x-ray, @nodesecure/rc, @nodesecure/scanner and @topcli/spinner.
Updates @nodesecure/js-x-ray from 8.2.0 to 10.1.0
Release notes
Sourced from @nodesecure/js-x-ray's releases.
@nodesecure/js-x-ray@10.1.0Minor Changes
Patch Changes
@nodesecure/js-x-ray@10.0.0Major Changes
- #383
09c3575Thanks@clemgbld! - feat(tracer): support tracking function return valuesMinor Changes
#399
857308cThanks@clemgbld! - feat(probes) add minimal implementation of data-exfiltration#392
02a2d05Thanks@fraxken! - Simplify tracing validation & add new spread test for the probe#398
b6d2474Thanks@fraxken! - Implement new pipeline mechanism with a built-in deobfuscate#382
bc62d3eThanks@clemgbld! - feat(probes): add finalize callback#397
283d5b6Thanks@fraxken! - Integrate estree-walker natively using meriyah ESTree types#387
4d097ccThanks@fraxken! - Move trojan-source detection from SourceFile to AstAnalyser#396
f66af80Thanks@fraxken! - Move Signals into probe.main context#380
99fd4feThanks@clemgbld! - refactor(probes): isFetch detect fetch re-assigment#395
fad019fThanks@fraxken! - Implement context for Probe and ProbeRunner#389
f037105Thanks@clemgbld! - feat(probes): isLiteral detect api.ipify.org with shady link#384
728d744Thanks@fraxken! - move ProbeRunner from SourceFile to AstAnalyser classPatch Changes
... (truncated)
Commits
f4da076chore: update versions (#408)07dc2a4chore(deps): bump openai in the dependencies group across 1 directory (#409)71c96d1chore: update frequency-set to v2.1.x (#407)b52c5c2chore(deps): bump the github-actions group with 6 updates (#405)8ba1aa2feat(js-x-ray-ai): implement a workspace to combine ai + js-X-ray (#404)4a4154bchore(deps): bump string-width in the dependencies group (#403)683b5fechore(deps): bump the github-actions group with 2 updates (#402)f5b9964chore(scripts): replace all clean script by open-ally clear-ts-build script (...f61651bchore: update versions (#378)857308cfeat(probes): add minimal implementation of data exfiltration (#399)- Additional commits viewable in compare view
Updates @nodesecure/rc from 4.1.0 to 5.0.1
Release notes
Sourced from @nodesecure/rc's releases.
@nodesecure/rc@5.0.1Patch Changes
@nodesecure/rc@5.0.0Major Changes
Commits
- See full diff in compare view
Updates @nodesecure/scanner from 6.12.1 to 7.2.0
Release notes
Sourced from @nodesecure/scanner's releases.
@nodesecure/scanner@7.2.0Minor Changes
#544
281c720Thanks@clemgbld! - feat(scanner): add npm token based on registry for sdk calls#542
49c5bbbThanks@fraxken! - Improve type-squatting global-warning by removing it on remote scan and also when there is to much similar packages
@nodesecure/scanner@7.1.0Minor Changes
#535
746c0fdThanks@clemgbld! - feat(scanner): implement dependency confusion detection#540
6105c7fThanks@clemgbld! - feat(scanner): add dependency warning only when getting a 404 from the public npm registry#541
dadb7fbThanks@fraxken! - Keep NPM provenance (attestations) in Dependency versionPatch Changes
@nodesecure/scanner@7.0.0Major Changes
Patch Changes
Commits
b12281bchore: update versions (#543)281c720feat(scanner): add npm token based on registry for sdk calls (#544)49c5bbbrefactor(typo-squatting): remove on local scan or when similar >= 3 (#542)5765023chore: update versions (#527)dadb7fbfeat(scanner): keep NPM provenance (attestations) in the dependency version (...728e2a1chore(deps-dev): bump the development-dependencies group across 1 directory w...cfce49echore(deps): bump the dependencies group across 1 directory with 4 updates (#...6105c7ffeat(scanner): add dependency warning only when getting a 404 from the public...a02664fMerge pull request #538 from NodeSecure/upt-frequency-setd20e27achore: update frequency-set to v2.x- Additional commits viewable in compare view
Updates @topcli/spinner from 3.0.0 to 4.0.0
Release notes
Sourced from @topcli/spinner's releases.
v4.0.0
What's Changed
- chore(dependabot): use groups by
@fraxkenin TopCli/Spinner#202- chore: update & pin (save-exact) cli-spinners dependency by
@fraxkenin TopCli/Spinner#210- fix: spinner name always shows the default one by
@sistemicoin TopCli/Spinner#212New Contributors
@sistemicomade their first contribution in TopCli/Spinner#212Full Changelog: https://github.com/TopCli/Spinner/compare/v3.0.0...v4.0.0
Commits
e40fe474.0.01451b71fix: spinner name always shows the default one (#212)67f7b4dchore(deps): bump the github-actions group with 4 updates (#211)c05cdfachore: update & pin (save-exact) cli-spinners dependency (#210)49ef286chore(deps): bump the github-actions group with 4 updates (#209)6060299chore(deps): bump the github-actions group with 4 updates (#208)5f6e67dchore(dependabot): use groups (#202)c70fc44chore(deps-dev): bump@types/nodein the development-dependencies group (#199)09e6bd5chore(deps): bump github/codeql-action from 3.28.18 to 3.29.11 (#206)51d0accrefactor!: rename interface starting with I Maj (#203)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) -
@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) -
@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) -
@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency -
@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions