Skip to content

Add updated codama-backend SDK across rust and typescript#38

Open
jeff-sqds wants to merge 5 commits into
mainfrom
feat/codama-sdk
Open

Add updated codama-backend SDK across rust and typescript#38
jeff-sqds wants to merge 5 commits into
mainfrom
feat/codama-sdk

Conversation

@jeff-sqds
Copy link
Copy Markdown

This PR introduces a Codama-based SDK for both rust and typescript. The typescript SDK is introduced alongside the existing one to allow for migration and deprecation gracefully.

NOTE: This PR relies on updating the IDL to parity with the current code (the current main branch IDL is stale against the tip of main program code) which itself requires temporarily updating anchor and the solana dependencies to allow building a working anchor toolchain on a recent rust version. with the new anchor-generated IDL, Codama was run to generate the new sdk/rust and sdk/ts directories.

The Codama code is also unable to generate full parity SDK components covering the custom events strategy of the smart account program so a complimentary sdk/rust/src/helpers module, feature-gated is added to provide missing functionality relative to the generated code and temporarily moved/preserved whenever the codama code is regenerated.

@socket-security
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: cargo icu_collections under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_collections-2.2.0/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_collections-2.2.0/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/icu_collections@2.2.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_collections@2.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_locale_core under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_locale_core-2.2.0/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_locale_core-2.2.0/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/icu_locale_core@2.2.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_locale_core@2.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_normalizer_data under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_normalizer_data-2.2.0/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_normalizer_data-2.2.0/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/icu_normalizer_data@2.2.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_normalizer_data@2.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_normalizer under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_normalizer-2.2.0/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_normalizer-2.2.0/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/icu_normalizer@2.2.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_normalizer@2.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_properties_data under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_properties_data-2.2.0/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_properties_data-2.2.0/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/icu_properties_data@2.2.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_properties_data@2.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_properties under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_properties-2.2.0/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_properties-2.2.0/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/icu_properties@2.2.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_properties@2.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_provider under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_provider-2.2.0/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (icu_provider-2.2.0/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/icu_provider@2.2.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_provider@2.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo litemap under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (litemap-0.8.2/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (litemap-0.8.2/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/litemap@0.8.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/litemap@0.8.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo potential_utf under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (potential_utf-0.1.5/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (potential_utf-0.1.5/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/potential_utf@0.1.5

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/potential_utf@0.1.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo tinystr under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (tinystr-0.8.3/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (tinystr-0.8.3/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/tinystr@0.8.3

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/tinystr@0.8.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo unicode-ident under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (unicode-ident-1.0.24/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (unicode-ident-1.0.24/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (unicode-ident-1.0.24/LICENSE-UNICODE)

From: ?cargo/solana-rpc-client@3.0.14cargo/thiserror@2.0.18cargo/solana-message@3.1.0cargo/solana-transaction@3.1.0cargo/borsh@1.6.1cargo/solana-address@2.6.0cargo/solana-instruction@3.4.0cargo/anchor-lang@0.31.1cargo/solana-account@3.0.0cargo/serde@1.0.228cargo/solana-hash@3.1.0cargo/unicode-ident@1.0.24

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/unicode-ident@1.0.24. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo webpki-roots under CDLA-Permissive-2.0

License: CDLA-Permissive-2.0 - The applicable license policy does not permit this license (5) (webpki-roots-1.0.7/Cargo.toml)

License: CDLA-Permissive-2.0 - The applicable license policy does not permit this license (5) (webpki-roots-1.0.7/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/webpki-roots@1.0.7

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/webpki-roots@1.0.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo writeable under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (writeable-0.6.3/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (writeable-0.6.3/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/writeable@0.6.3

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/writeable@0.6.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo yoke-derive under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (yoke-derive-0.8.2/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (yoke-derive-0.8.2/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/yoke-derive@0.8.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/yoke-derive@0.8.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo yoke under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (yoke-0.8.2/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (yoke-0.8.2/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/yoke@0.8.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/yoke@0.8.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zerofrom-derive under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (zerofrom-derive-0.1.7/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (zerofrom-derive-0.1.7/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/zerofrom-derive@0.1.7

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zerofrom-derive@0.1.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zerofrom under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (zerofrom-0.1.8/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (zerofrom-0.1.8/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/zerofrom@0.1.8

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zerofrom@0.1.8. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zerotrie under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (zerotrie-0.2.4/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (zerotrie-0.2.4/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/zerotrie@0.2.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zerotrie@0.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zerovec-derive under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (zerovec-derive-0.11.3/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (zerovec-derive-0.11.3/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/zerovec-derive@0.11.3

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zerovec-derive@0.11.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zerovec under Unicode-3.0

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (zerovec-0.11.6/Cargo.toml)

License: Unicode-3.0 - The applicable license policy does not permit this license (5) (zerovec-0.11.6/LICENSE)

From: ?cargo/solana-rpc-client@3.0.14cargo/zerovec@0.11.6

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zerovec@0.11.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zstd-sys under GPL-2.0+

License: GPL-2.0+ - The applicable license policy does not permit this license (5) (zstd-sys-2.0.16+zstd.1.5.7/zstd/COPYING)

From: ?cargo/solana-rpc-client@3.0.14cargo/zstd-sys@2.0.16%2Bzstd.1.5.7

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zstd-sys@2.0.16%2Bzstd.1.5.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm typescript under CC-BY-4.0

License: CC-BY-4.0 - The applicable license policy does not permit this license (5) (package/ThirdPartyNoticeText.txt)

License: MIT-Khronos-old - The applicable license policy does not permit this license (5) (package/ThirdPartyNoticeText.txt)

License: LicenseRef-W3C-Community-Final-Specification-Agreement - The applicable license policy does not permit this license (5) (package/ThirdPartyNoticeText.txt)

From: sdk/ts/package-lock.jsonnpm/typescript@5.9.3

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/typescript@5.9.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant