-
Notifications
You must be signed in to change notification settings - Fork 281
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
lerna/8.1.4 package update #21636
lerna/8.1.4 package update #21636
Conversation
octo-sts
bot
commented
Jun 9, 2024
Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
Package lerna: Click to expand/collapsePackage lerna:
Added: /usr/local/lib/node_modules/lerna/dist/libs/child-process/src/index.d.ts bincapz found differences: Click to expand/collapseDeleted: lerna/usr/local/lib/node_modules/lerna/.nx/cache/19.0.2-nx.linux-x64-gnu.node [🔥 HIGH]Deleted: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/server/handle-request-file-data.js [✅ LOW]
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/schema/failsafe.js [✅ LOW]
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/server/handle-glob.js [✅ LOW]
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/sprintf-js/dist/angular-sprintf.min.js [✅ LOW]
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/argparse/lib/action_container.js [
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./action ./argument ./const ./utils |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/diff/src/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/index.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/nodeca/js-yaml |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/schema/json.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTP URLs | http://www.yaml.org/spec/1.2/spec.html |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/sprintf-js/src/sprintf.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | techniques/code_eval | evaluate code dynamically using exec() | exec(replacement |
+LOW | encoding/json/encode | encodes JSON | JSON.stringify |
Added: lerna/usr/local/lib/node_modules/lerna/dist/packages/lerna/src/commands/add-caching/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/scm-clients/index.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./github ./gitlab |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/server/handle-nx-workspace-files.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | encoding/json/encode | encodes JSON | JSON.stringify |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/legacy-core/src/lib/command/index.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/cmd | executes a command | runCommand |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/child-process/src/index.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | techniques/code_eval | evaluate code dynamically using exec() | exec(command |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/schema/default_safe.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTP URLs | http://yaml.org/type/ |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/write-log-file.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | fs/file/write | writes to file | writeLogFile |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/server/handle-hash-glob.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./server |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/npm-conf/conf.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/words/password | references a 'password' | password |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/argparse/lib/argparse.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./action ./argument_parser ./const ./help ./namespace |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/exec/src/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/axios/lib/helpers/resolveConfig.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/http/cookies | access HTTP resources using cookies | Cookie HTTP |
+LOW | ref/words/password | references a 'password' | password |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/server/handle-context-file-data.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./server |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/schema/default_full.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/exclamation | gets very excited | regexp and !! |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/legacy-core/src/lib/get-filtered-packages.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./package-graph |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/loader.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./common ./exception ./mark ./schema |
+MEDIUM | techniques/code_eval | evaluate code dynamically using exec() | exec(args |
+LOW | evasion/bitwise_math | uses bitwise math | esult << 4 |
+LOW | net/hostname/resolve | resolve network host name to IP address | cannot resolve |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://en.wikipedia.org/wiki/UTF-16 |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/run-lifecycle.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./package |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/conventional-commits/index.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./update-changelog |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/axios/lib/adapters/fetch.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | onDownloadProgress |
+MEDIUM | net/upload | uploads files | UploadProgress |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/server/handle-nx-workspace-files.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./server |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/argparse/lib/action/store/false.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./constant |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/dumper.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./common ./exception ./schema |
+MEDIUM | techniques/code_eval | evaluate code dynamically using exec() | exec(line))) exec(string))) |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/nx-cloud/utilities/url-shorten.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/socket/connect | initiate a connection on a socket | connect |
+MEDIUM | ref/words/exclamation | gets very excited | return !! |
+LOW | env/get | Retrieve environment variable values | env.NRWL |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://cloud.nx.app |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/server/handle-get-files-in-directory.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./server |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/legacy-core/src/lib/package-graph/cyclic-package-graph-node.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | fs/file/delete | deletes files | unlink |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/npm-publish.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./otplease ./package |
+LOW | ref/words/password | references a 'password' | OneTimePasswordCache |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/legacy-core/src/lib/query-graph.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./package-graph |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/legacy-core/src/lib/run-topologically.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./query-graph |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/type/binary.js [⚠️ MEDIUM]
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/argparse/index.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./lib |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/index.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./lib |
+LOW | ref/words/password | references a 'password' | getOneTimePassword |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./js-yaml |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/utils/get-package-name-from-import-path.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/words/plugin | references a 'plugin' | plugin |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/is-on-daemon.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/words/exclamation | gets very excited | return !! |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/listable-options.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./project |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/info/src/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/dist/js-yaml.min.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | techniques/code_eval | evaluate code dynamically using exec() | exec(e)),null exec(e),e exec(n exec(t) |
+LOW | net/hostname/resolve | resolve network host name to IP address | cannot resolve |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/nodeca/js-yaml |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/conventional-commits/constants.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://conventionalcommits.org |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/project-graph-with-packages.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./package |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/plugins/js/utils/resolve-relative-to-dir.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | jestjs/jest#9543 |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/argparse/lib/action.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/dev | path reference within /dev | /dev/library/argparse |
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./const |
+LOW | ref/site/url | contains embedded HTTP URLs | http://docs.python.org/dev/library/argparse.html |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/list/src/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/run/src/command.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/cmd | executes a command | RunCommandConfigOptions |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/otplease.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/words/password | references a 'password' | OneTimePasswordCache for one-time password getOneTimePassword |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/command/index.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/cmd | executes a command | runCommand |
+MEDIUM | ref/words/exclamation | gets very excited | Can be removed when latest execa version is used!!! |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/server/handle-get-files-in-directory.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | encoding/json/encode | encodes JSON | JSON.stringify |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/server/handle-glob.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./server |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/conventional-commits/get-changelog-config.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./constants |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/schema/core.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTP URLs | http://www.yaml.org/spec/1.2/spec.html |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/init/src/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/exec/src/index.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/cmd | executes a command | ExecCommandConfigOptions runCommandInPackageCapturing runCommandInPackageStreaming runCommandInPackagesLexical runCommandInPackagesParallel runCommandInPackagesTopological |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/index.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | kernel/platform | get system identification | process.platform |
+MEDIUM | techniques/code_eval | evaluate code dynamically using exec() | exec(string) |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/argparse/lib/argument/error.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./argument |
Added: lerna/usr/local/lib/node_modules/lerna/dist/packages/lerna/src/commands/repair/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/type.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./exception |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/exception.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTP URLs | http://stackoverflow.com/questions/8458984 |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/bin/js-yaml.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | encoding/json/decode | Decodes JSON messages | JSON.parse |
+LOW | encoding/json/encode | encodes JSON | JSON.stringify |
+LOW | fs/file/read | reads files | fs.readFile |
+LOW | ref/path/usr/bin | path reference within /usr/bin | /usr/bin/env |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/plugins/js/utils/resolve-relative-to-dir.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | jestjs/jest#9543 |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/dist/js-yaml.js [🔥 HIGH]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+HIGH | evasion/bitwise_math | excessive use of bitwise math | bits << 2 bits << 4 bits << 6 bits << 8 esult << 4 |
+MEDIUM | ref/words/exclamation | gets very excited | regexp and !! |
+MEDIUM | techniques/code_eval | evaluate code dynamically using exec() | exec(args exec(data), exec(line))) exec(string))) |
+LOW | net/hostname/resolve | resolve network host name to IP address | cannot resolve |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://en.wikipedia.org/wiki/UTF-16 https://github.com/nodeca/js-yaml |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/package.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./pack-directory |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/version/src/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/dist/packages/lerna/src/commands/watch/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/changed/src/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/argparse/lib/help/formatter.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/dev | path reference within /dev | /dev/library/argparse |
+MEDIUM | ref/words/exclamation | gets very excited | return !! |
+MEDIUM | techniques/code_eval | evaluate code dynamically using exec() | exec(line |
+LOW | env/get | Retrieve environment variable values | env.COLUMNS |
+LOW | ref/site/url | contains embedded HTTP URLs | http://docs.python.org/dev/library/argparse.html |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/argparse/lib/argument_parser.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/dev | path reference within /dev | /dev/library/argparse |
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./action_container ./argument ./const ./help ./namespace ./utils |
+LOW | fs/file/read | reads files | fs.readFile |
+LOW | ref/site/url | contains embedded HTTP URLs | http://docs.python.org/dev/library/argparse.html |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/command-line/deprecated/command-objects.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | fd/multiplex | monitor multiple file descriptors | select |
Added: lerna/usr/local/lib/node_modules/lerna/dist/packages/lerna/src/utils/index.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./detect-projects |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/legacy-core/src/lib/symlink-dependencies.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./package-graph |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/import/src/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/clean/src/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/filter-projects.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./filter-options |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/argparse/lib/argument/exclusive.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./group |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/legacy-core/src/lib/package-graph/package-graph-node.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/npm/npm-package-arg |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/server/handle-hash-glob.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | encoding/json/encode | encodes JSON | JSON.stringify |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/axios/lib/helpers/progressEventReducer.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | download isDownloadStream |
+MEDIUM | net/upload | uploads files | upload |
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./speedometer ./throttle |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/command-line/release/plan.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | fs/file/write | writes to file | writeFile |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/sprintf-js/dist/sprintf.min.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | techniques/code_eval | evaluate code dynamically using exec() | exec(b)))d exec(b)))throw exec(h)))g exec(h)))throw |
+LOW | encoding/json/encode | encodes JSON | JSON.stringify |
+LOW | ref/site/url | contains embedded HTTP URLs | http://alexei.ro/ |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/type/timestamp.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | techniques/code_eval | evaluate code dynamically using exec() | exec(data) |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/run/src/index.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/cmd | executes a command | RunCommandConfigOptions |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/pack-directory.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./package |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/legacy-core/src/index.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./lib |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/daemon/server/handle-context-file-data.js [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | encoding/json/encode | encodes JSON | JSON.stringify |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/commands/publish/src/command.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/yargs/yargs/blob/master/docs/advanced.md |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/argparse/lib/namespace.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/dev | path reference within /dev | /dev/library/argparse |
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./utils |
+LOW | ref/site/url | contains embedded HTTP URLs | http://docs.python.org/dev/library/argparse.html |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/type/js/regexp.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | techniques/code_eval | evaluate code dynamically using exec() | exec(data), |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/listable-format-projects.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./listable-options |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/schema.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./common ./exception ./type |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/argparse/lib/action/store/true.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./constant |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/index.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./lib |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/nx/src/command-line/release/plan.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./command-object |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/core/src/lib/cycles/index.d.ts [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./get-cycles ./report-cycles |
Added: lerna/usr/local/lib/node_modules/lerna/dist/libs/legacy-core/src/lib/write-log-file.d.ts [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | fs/file/write | writes to file | writeLogFile |
Added: lerna/usr/local/lib/node_modules/lerna/node_modules/front-matter/node_modules/js-yaml/lib/js-yaml/mark.js [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/path/relative | references and possibly executes relative path | ./common |
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/handlebars/dist/amd/handlebars/compiler/parser.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/handlebars/dist/amd/handlebars/no-conflict.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/@sigstore/sign/dist/witness/tlog/index.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/pacote/node_modules/@sigstore/sign/dist/witness/tlog/index.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/pacote/node_modules/ssri/lib/index.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/@sigstore/verify/dist/tlog/hashedrekord.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/make-fetch-happen/node_modules/ssri/lib/index.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/tar/lib/create.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/@yarnpkg/parsers/node_modules/js-yaml/dist/js-yaml.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/typescript/lib/lib.webworker.d.ts
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/chardet/encoding/mbcs.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/handlebars/dist/amd/handlebars/internal/wrapHelper.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/js-yaml/dist/js-yaml.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/handlebars/dist/cjs/handlebars/compiler/parser.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/source-map/dist/source-map.debug.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/tuf-js/node_modules/ssri/lib/index.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/@sigstore/verify/dist/tlog/dsse.js
Changed: lerna/usr/local/lib/node_modules/lerna/node_modules/@nx/nx-linux-x64-gnu/nx.linux-x64-gnu.node
1 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | process/create | create child process | _fork |
2 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/cmd | executes a command | rsrunCommandRustPseudoTerminal |
-LOW | fs/mount | mounts file systems | -o mount |