Skip to content
This repository has been archived by the owner on Jun 25, 2024. It is now read-only.

[INT-7879]: bump googleapis version #610

Merged
merged 34 commits into from
Jun 13, 2023

Conversation

mishelashala
Copy link

No description provided.

@mishelashala mishelashala requested a review from a team as a code owner May 31, 2023 16:38
@mishelashala mishelashala self-assigned this May 31, 2023
@socket-security
Copy link

socket-security bot commented May 31, 2023

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Issue Package Version Note Source
Network access express 4.18.2 package.json via @jupiterone/[email protected], @jupiterone/[email protected]

Next steps

What is network access?

This module accesses the network.

Packages should remove all network access that isn't functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore [email protected] bar@* or ignore all packages with @SocketSecurity ignore-all

@mishelashala mishelashala added minor Increment the minor version when merged release Create a release when this pr is merged labels Jun 5, 2023
adam-in-ict
adam-in-ict previously approved these changes Jun 5, 2023
adam-in-ict
adam-in-ict previously approved these changes Jun 5, 2023
@socket-security
Copy link

New and updated dependency changes detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives1 Size Publisher
ts-node 🆕 10.9.1 shell, environment +13 70 MB cspotcode
@jupiterone/integration-sdk-dev-tools ⬆️ 8.37.0...8.41.0 None +212/-178 208 MB jupiterone-dev
@jupiterone/integration-sdk-testing ⬆️ 8.37.0...8.41.0 None +73/-62 95 MB jupiterone-dev
node-fetch ⬆️ 2.6.1...2.6.11 None +0/-0 162 kB node-fetch-bot
@jupiterone/integration-sdk-core ⬆️ 8.37.0...8.41.0 None +3/-3 1.3 MB jupiterone-dev
googleapis ⬆️ 94.0.0...118.0.0 filesystem +18/-17 131 MB google-wombot
@types/bunyan-format ⬆️ 0.2.3...0.2.5 None +1/-1 1.59 MB types
@types/bunyan ⬆️ 1.8.6...1.8.8 None +1/-1 1.59 MB types
@types/node-fetch ⬆️ 2.5.10...2.6.4 None +3/-3 1.82 MB types
gaxios ⬆️ 4.3.0...4.3.3 None +3/-4 262 kB google-wombot
cac ⬆️ 6.7.3...6.7.14 None +0/-0 81.8 kB egoist
google-auth-library ⬆️ 7.1.1...8.8.0 filesystem, environment +10/-11 2.95 MB google-wombot
auto ⬆️ 10.37.4...10.46.0 None +50/-36 78.5 MB alisowski

🚮 Removed packages: @lifeomic/[email protected]

Footnotes

  1. https://docs.socket.dev

@mishelashala mishelashala merged commit 4c11d59 into main Jun 13, 2023
@mishelashala mishelashala deleted the INT-7879/bump-googleapis-version branch June 13, 2023 19:17
@j1-internal-automation
Copy link
Collaborator

🚀 PR was released in v2.30.0 🚀

@j1-internal-automation j1-internal-automation added the released This issue/pull request has been released. label Jun 13, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
minor Increment the minor version when merged release Create a release when this pr is merged released This issue/pull request has been released.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants