Skip to content

Version Packages - #13254

Merged
raymondjacobson merged 1 commit into
mainfrom
changeset-release/main
Oct 23, 2025
Merged

Version Packages#13254
raymondjacobson merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 15, 2025

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@audius/sdk@11.1.0

Minor Changes

  • 8b3380f: Add all time coin stats to coins api responses

Patch Changes

  • a6d5e9d: Add validator type and regen bootstrap list
  • c3ffa17: remove dbc_pool from createCoin
  • 86198ae: add coin_flair_mint field to user response
  • Updated dependencies [284302b]
    • @audius/spl@2.1.0

@audius/spl@2.1.0

Minor Changes

  • 284302b: add revoke manager instructions

@audius/sdk-legacy@6.0.11

Patch Changes

  • Updated dependencies [a6d5e9d]
  • Updated dependencies [8b3380f]
  • Updated dependencies [c3ffa17]
  • Updated dependencies [284302b]
  • Updated dependencies [86198ae]
    • @audius/sdk@11.1.0
    • @audius/spl@2.1.0

@audius/sp-actions@1.0.15

Patch Changes

  • @audius/sdk-legacy@6.0.11

@github-actions
github-actions Bot force-pushed the changeset-release/main branch 8 times, most recently from a8ab03a to 0e16e52 Compare October 22, 2025 00:34
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 0e16e52 to 9761828 Compare October 23, 2025 15:56
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 9761828 to 2fe382d Compare October 23, 2025 17:48
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​@​babel/​helper-annotate-as-pure@​7.25.91001006589100
Updatednpm/​@​apollo/​utils.removealiases@​1.0.0 ⏵ 2.0.11001006881100
Updatednpm/​@​babel/​helper-hoist-variables@​7.16.7 ⏵ 7.22.5100 +110070 +182100
Updatednpm/​@​babel/​helper-environment-visitor@​7.16.7 ⏵ 7.22.20100 +110070 +482100
Updatednpm/​@​babel/​helper-split-export-declaration@​7.16.7 ⏵ 7.22.6100 +110070 +182100
Addednpm/​@​babel/​plugin-proposal-class-static-block@​7.21.01001007182100
Updatednpm/​@​babel/​helper-plugin-utils@​7.17.12 ⏵ 7.26.510010071 +189100
Updatednpm/​@​apollo/​utils.printwithreducedwhitespace@​1.1.0 ⏵ 2.0.110010071 +881100
Updatednpm/​@​babel/​helper-validator-option@​7.16.7 ⏵ 7.27.110010071 +194 +5100
Updatednpm/​@​babel/​highlight@​7.17.12 ⏵ 7.23.4100 +110072 +182100
Updatednpm/​@​apollo/​utils.sortast@​1.1.0 ⏵ 2.0.110010072 +881100
Addednpm/​@​babel/​preset-typescript@​7.22.151001007289100
Updatednpm/​@​babel/​helper-validator-identifier@​7.16.7 ⏵ 7.28.51001007395 +7100
Updatednpm/​@​babel/​helper-function-name@​7.17.9 ⏵ 7.23.010010073 +182100
Addednpm/​@​babel/​register@​7.7.0991007389100
Updatednpm/​@​babel/​code-frame@​7.16.7 ⏵ 7.27.110010074 +194 +5100
Updatednpm/​@​babel/​plugin-transform-runtime@​7.18.0 ⏵ 7.18.2991007491100
Updatednpm/​@​babel/​helper-compilation-targets@​7.17.10 ⏵ 7.27.110010075 +190100
Updatednpm/​@​apollo/​utils.stripsensitiveliterals@​1.2.0 ⏵ 2.0.110010075 +1081100
Addednpm/​@​audius/​fetch-nft@​0.2.8751009984100
Updatednpm/​@​babel/​helper-module-imports@​7.16.7 ⏵ 7.27.110010075 +194 +5100
Addednpm/​@​babel/​plugin-transform-react-jsx@​7.21.01001007689100
Updatednpm/​@​apollo/​utils.dropunuseddefinitions@​1.1.0 ⏵ 2.0.110010076 +1281100
Updatednpm/​@​babel/​template@​7.16.7 ⏵ 7.27.1100 +110076 +190 +1100
Updatednpm/​@​babel/​helper-define-polyfill-provider@​0.3.1 ⏵ 0.3.3100 +11007684100
Updatednpm/​@​apollo/​utils.usagereporting@​1.0.1 ⏵ 2.1.01001007681100
Addednpm/​@​babel/​cli@​7.7.0991007693100
Addednpm/​@​babel/​preset-env@​7.22.15961007791100
Addednpm/​@​audius/​stems@​0.3.10771009384100
Addednpm/​@​babel/​helper-module-transforms@​7.27.11001007790100
Addednpm/​@​certusone/​wormhole-sdk@​0.1.18110010078100
Updatednpm/​@​babel/​parser@​7.18.0 ⏵ 7.27.110010078 -293100
See 23 more rows in the dashboard

View full report

@socket-security

Copy link
Copy Markdown

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Low
npm/@amplitude/session-replay-browser@1.15.1 is a AI-detected potential code anomaly.

Notes: This is a session-replay / DOM-capture library that intentionally collects detailed page state (DOM, canvas bitmaps, user interactions), persists them locally, compresses, and sends them to Amplitude session-replay endpoints. The behavior is expected for such SDKs. The primary security concern is privacy/data exfiltration: if misconfigured or used without user consent, the library can capture sensitive inputs and page content. No evidence of traditional malware (reverse shell, arbitrary remote code execution, eval-based payloads) was found in the provided fragment. Recommendations: only use from trusted package sources, ensure masking/ignore selectors are tightly configured (especially for inputs and sensitive CSS selectors), review remote config behavior (it fetches sampling/privacy config), consider privacy/legal implications (consent), and monitor network endpoints and API keys.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/@amplitude/plugin-session-replay-browser@1.8.2npm/@amplitude/session-replay-browser@1.15.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@amplitude/session-replay-browser@1.15.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@audius/hedgehog@3.0.0-alpha.1 is a AI-detected potential code anomaly.

Notes: The source code contains hardcoded sensitive credentials and cryptographic material that are directly exported, posing a high security risk if used in production or published publicly. There is no evidence of malware or obfuscation, but the insecure practice of embedding plaintext passwords and keys in source code can lead to credential leakage and compromise. It is strongly recommended to remove hardcoded secrets, implement secure credential management, and restrict exposure of sensitive data.

Confidence: 1.00

Severity: 0.60

From: monitoring/prometheus/package-lock.jsonnpm/@audius/hedgehog@3.0.0-alpha.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@audius/hedgehog@3.0.0-alpha.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@babel/core@7.23.7 is a AI-detected potential code anomaly.

Notes: The analyzed code fragment is a standard Babel core error handling and code-frame rendering utility. It reads internal node and code data to produce informative errors but does not perform any suspicious network activity, data exfiltration, or backdoor behavior. The observed behavior is typical for a compiler/transpiler component and, in this isolated context, does not indicate malicious activity.

Confidence: 0.75

Severity: 0.50

From: package-lock.jsonnpm/@babel/core@7.23.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/core@7.23.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@babel/core@7.23.7 is a AI-detected potential code anomaly.

Notes: The analyzed fragment implements a conventional file transformation entry point with no evident malicious behavior or hard-coded secrets. Security concerns depend on the downstream transformation logic (run) and configuration loading (loadConfig). The code maintains safe control flow (null config handling) and avoids arbitrary code execution within this scope.

Confidence: 0.72

Severity: 0.58

From: package-lock.jsonnpm/@babel/core@7.23.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/core@7.23.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@babel/helper-function-name@7.23.0 is a AI-detected potential code anomaly.

Notes: No evidence of malicious behavior or supply chain abuse. The code is a conventional Babel AST transformation helper that preserves function identity and avoids local binding collisions. It operates entirely within the transformation context and does not perform network I/O, data exfiltration, or code execution from untrusted input.

Confidence: 1.00

Severity: 0.60

From: monitoring/prometheus/package-lock.jsonnpm/@babel/helper-function-name@7.23.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helper-function-name@7.23.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@babel/helper-module-imports@7.27.1 is a AI-detected potential code anomaly.

Notes: The analyzed code is a Babel AST helper (ImportBuilder) used to construct import statements and interop-wrapped imports. It contains no indicators of malicious behavior, data exfiltration, backdoors, or runtime abuses. It operates within a compiler/transpiler context to produce code, not to execute arbitrary user data. Therefore, the code itself does not present security risks or malware indicators under normal usage. This is benign library behavior intended for code transformation.

Confidence: 1.00

Severity: 0.60

From: monitoring/prometheus/package-lock.jsonnpm/@babel/helper-module-imports@7.27.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helper-module-imports@7.27.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@babel/helper-module-transforms@7.27.1 is a AI-detected potential code anomaly.

Notes: The code is a legitimate, static-code transformation utility used in Babel to ensure proper behavior of ES module bindings after transforms. There is no evidence of malicious behavior, data leakage, or external communications within this fragment. It operates purely on AST-level transformations consistent with module import/export handling.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/@babel/helper-module-transforms@7.27.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helper-module-transforms@7.27.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@babel/helper-string-parser@7.27.1 is a AI-detected potential code anomaly.

Notes: The analyzed code is a standard, well-structured parsing utility for JavaScript string literals and escapes (consistent with Babel’s helper-string-parser). It includes thorough validation, proper Unicode handling, and defensive error reporting. There is no evidence of malicious behavior, data leakage, or network activity within this fragment. The security risk is low when used as part of a trusted toolchain; the code otherwise poses no evident supply-chain threat based on the provided snippet.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/@babel/helper-string-parser@7.27.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helper-string-parser@7.27.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@babel/helpers@7.27.1 is a AI-detected potential code anomaly.

Notes: The analyzed fragment is a conventional Babel/TypeScript-style decorators runtime (applyDecs) responsible for applying decorators to class members and managing metadata and initializers. There is no evidence of malware, backdoors, or external data leakage within this module. While complex, the code behaves as a metadata-driven decorator processor and should be considered low risk when used as intended. Downstream risks depend on the decorators provided by consumers, not this utility itself.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/@babel/helpers@7.27.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helpers@7.27.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@babel/plugin-syntax-typescript@7.25.9 is a AI-detected potential code anomaly.

Notes: The code is a standard Babel plugin fragment that configures syntax support for TypeScript by manipulating parser plugins. There is no malicious logic, no data exfiltration, and no unsafe operations. It appears to be a legitimate helper for enabling TypeScript syntax in Babel pipelines.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/@babel/preset-typescript@7.22.15npm/@babel/plugin-syntax-typescript@7.25.9

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/plugin-syntax-typescript@7.25.9. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@babel/runtime@7.18.3 is a AI-detected potential code anomaly.

Notes: The module implements a legitimate Babel runtime polyfill for named capture groups, using established patterns (WeakMap, prototype inheritance, lazy initialization) to augment RegExp results and substitutions. No evidence of malicious activity, data leakage, or external communication. Overall security risk is low but the code warrants standard review for potential debugging complexity due to prototype and factory redefinition.

Confidence: 1.00

Severity: 0.60

From: monitoring/prometheus/package-lock.jsonnpm/@babel/runtime@7.18.3

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/runtime@7.18.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@babel/runtime@7.24.0 is a AI-detected potential code anomaly.

Notes: Selected report 1 provides a thorough evaluation of decorator-related runtime utilities and concludes low risk with potential for finishers to alter constructors if used with untrusted inputs. The improved assessment confirms normal, expected behavior for Babel decorator infrastructure and notes that the primary risk lies in the finishers channel if untrusted code is supplied. Security risk remains low to moderate depending on input provenance; malware likelihood is negligible based on the fragment.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/@changesets/cli@2.27.1npm/@babel/runtime@7.24.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/runtime@7.24.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/@certusone/wormhole-sdk@0.1.1 is a AI-detected potential code anomaly.

Notes: The analyzed code is a standard, autogenerated ethers.js ContractFactory for an NFTBridge contract. No malicious behavior detected within this fragment. Security posture is typical for library code; risk depends on the on-chain contract and provider configuration, not this loader.

Confidence: 0.75

Severity: 0.55

From: monitoring/prometheus/package-lock.jsonnpm/@certusone/wormhole-sdk@0.1.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@certusone/wormhole-sdk@0.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/axios@1.7.4 is a AI-detected potential code anomaly.

Notes: The code is a legitimate, self-contained throttling transformer designed for Axios-like streaming workflows. It throttles data output based on maxRate and timeWindow, preserves data integrity by splitting chunks when necessary, and emits optional progress telemetry. No malicious activity or data leakage is detected in this fragment. Security risk remains moderate due to throttling complexity and potential misconfiguration in real deployments, but the module itself does not introduce obvious security flaws.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/axios@1.7.4

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/axios@1.7.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/axios@1.7.4 is a AI-detected potential code anomaly.

Notes: The code appears to be a standard, well-scoped progress-event utility used to report progress (upload/download) to a consumer listener. It reads input from the event object and computes metrics, then forwards a structured payload to a listener. A minor data exposure risk exists due to passing the raw event object to the listener; mitigations include sanitizing the payload or removing the event object before emission. Overall security risk remains modest, with malware likelihood negligible in this isolated module.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/axios@1.7.4

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/axios@1.7.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/chalk@2.4.2 is a AI-detected potential code anomaly.

Notes: This is a conventional Chalk-like color-styling module. It exhibits expected behavior for terminal styling, uses environment checks for compatibility, and does not demonstrate malicious activity, data leakage, or external communications. Security risk is low in isolation; the primary considerations are safe usage in environments where ANSI sequences could affect log readability or concealment, and ensuring trusted template renderingCode integrity. Overall, the component appears benign within its described scope.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/@babel/highlight@7.23.4npm/chalk@2.4.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/chalk@2.4.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/got@11.8.6 is a AI-detected potential code anomaly.

Notes: The analyzed code fragment is a standard part of a HTTP client wrapper (Got) with typical features: option normalization, hooks, error mapping, proxies for handlers, pagination, and streaming. There is no evidence of malicious behavior (no data exfiltration, backdoors, environment-variable abuse, or covert network connections) within this isolated module. Security risk is low for this fragment, assuming the core implementation and extension ecosystem are trustworthy.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/got@11.8.6

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/got@11.8.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/semver@6.3.1 is a AI-detected potential code anomaly.

Notes: No malicious behavior detected. This is a legitimate SemVer utility implementation handling version validation, range filtering, and optional increments. Security risk is low for this code fragment; obfuscated indicators are absent. Overall malice likelihood is negligible.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/@babel/core@7.23.7npm/semver@6.3.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/semver@6.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
npm/uuid@8.3.2 is a AI-detected potential code anomaly.

Notes: The code is a straightforward MD5 hashing utility with standard input normalization. It does not exhibit malicious behavior or data exfiltration. The primary concern is MD5’s cryptographic weaknesses for security-sensitive contexts rather than any malware or backdoors. Suitable for non-security-critical hashing tasks; avoid MD5 for password storage or integrity checks in security-sensitive applications.

Confidence: 1.00

Severity: 0.60

From: package-lock.jsonnpm/@audius/hedgehog@3.0.0-alpha.1npm/uuid@8.3.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/uuid@8.3.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@raymondjacobson
raymondjacobson self-requested a review October 23, 2025 17:50
@raymondjacobson
raymondjacobson merged commit 6ed86b5 into main Oct 23, 2025
2 of 4 checks passed
@raymondjacobson
raymondjacobson deleted the changeset-release/main branch October 23, 2025 18:01
audius-infra pushed a commit that referenced this pull request Oct 25, 2025
[4b1ce10] [PE-7239] Fix issues due to stale local storage data (#13311) Dylan Jeffers
[7a88ddf] Artist coins page size 1000 (#13313) Reed
[3d246f6] Some additional analytics around wallets & launchpad (#13312) JD Francis
[f22659e] [PE-7238] Add analytics for external wallet swaps (#13309) JD Francis
[421a9e9] 💚🟢🐸🥬 (#13308) JD Francis
[ffb4af9] Fix wallet connect not triggering success in claim flow (#13305) JD Francis
[68fa1a4] [PE-7229] Fix referrer signup (#13306) Dylan Jeffers
[6ed86b5] Version Packages (#13254) github-actions[bot]
[b9b22cd] [PE-7204] Associate wallets on solana /relay calls (#13299) JD Francis
[ad01774] Revert "[PE-7211] Claim fees after connect" (#13303) JD Francis
[1819c1e] fix mobile ci (#13302) JD Francis
[afeceae] Fix AUDIO breakdown (#13298) Farid Salau
[68eace6] birdeye.so (#13301) Marcus Pasell
[30f3e66] [PE-7215] Add sol back into the list of tokens + Dont show 'add cash' (#13295) JD Francis
[6e74a41] Fix CI (#13297) Farid Salau
[e68b261] [PE-7212] Claim fees optimistic updates (#13290) Dylan Jeffers
[d1000f1] [PE-7211] Claim fees after connect (#13291) Dylan Jeffers
[f1f1e94] [PE-7210] Handle lowercase coin urls (#13284) Dylan Jeffers
[8eade23] [PE-7226] Fix issues with confirmation screen (#13294) JD Francis
[0b58a67] [PE-7198] Update mobile profile edit flow UI (#13271) Farid Salau
[dd17039] eth key exporter (#13293) alecsavvy
[a6d5e9d] Use production wAUDIO on stage (#13288) Marcus Pasell
[0bd603d] [PE-7213] Prevent claiming dust (#13289) Dylan Jeffers
[b4dde83] Add polling for audio balance changes (#13228) JD Francis
[315865f] Fix lint (#13285) Dylan Jeffers
[ee7ee7f] [PE-7209] External wallet coin dropdown (#13283) Dylan Jeffers
[d4f7649] [PE-7191] External wallet swap flow (#13276) JD Francis
[4a38e63] Rename asset to coin (#13275) Dylan Jeffers
[c3ffa17] Show DAMM V2 Fees in UI (#13280) Marcus Pasell
[172f129] Remove extra dbcpool arg (#13269) Ray Jacobson
[3dafa35] [PE-7199] Refactor buy/sell flow coin filtering logic  (#13272) Farid Salau
[c1d796d] [PE-7193] Announcement notifs link to artist coin explore (#13266) Reed
[3e561d2] [PE-7197] Update ArtistCoinHoverCard to include member vs creator  (#13270) Farid Salau
[50878b5] Small QA items (#13273) Farid Salau
[932fbdb] Remove search explore flag (#13261) Dylan Jeffers
[5da716e] [PE-7163] Redirect mispelled coins to 404 (#13274) Ray Jacobson
[6866949] Finalize mobile search explore (#13260) Dylan Jeffers
[0ec2f5f] [PE-7189] Add balance breakdown component  (#13262) Farid Salau
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant