Skip to content

Conversation

@ffmcgee725
Copy link
Member

Explanation

This PR modifies the current setup so that the playground can be built and deployed, to facilitate end-to-end testing.

References

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed, highlighting breaking changes as necessary
  • I've prepared draft pull requests for clients and consumer packages to resolve any breaking changes

@ffmcgee725 ffmcgee725 requested a review from a team as a code owner October 24, 2025 12:15
@socket-security
Copy link

socket-security bot commented Oct 24, 2025

No dependency changes detected. Learn more about Socket for GitHub.

👍 No dependency changes detected in pull request

@ffmcgee725
Copy link
Member Author

ffmcgee725 commented Oct 24, 2025

After manually reviewing bundled code from npm:registry-auth-token, I can say the code is safe for publishing.

The notes say 8 base64 encoded strings were found, which are commonly used to hide malicious payloads or obfuscate code. But these are actually just test code, and encoding regular strings like password or foobar.

@ffmcgee725
Copy link
Member Author

ffmcgee725 commented Oct 24, 2025

After manually reviewing bundled code from npm:arch, it makes sense that it has Shell access.

@ffmcgee725
Copy link
Member Author

@SocketSecurity ignore npm/[email protected]

@ffmcgee725
Copy link
Member Author

@SocketSecurity ignore npm/[email protected]

@ffmcgee725 ffmcgee725 merged commit ad48399 into main Oct 24, 2025
36 checks passed
@ffmcgee725 ffmcgee725 deleted the jc/WAPI-807 branch October 24, 2025 14:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants