Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Aug 6, 2024

This PR contains the following updates:

Package Type Update Change
@dimensionalpocket/development devDependencies major 0.7.01.3.0

🔡 If you wish to disable git hash updates, add ":disableDigestUpdates" to the extends array in your config.


Release Notes

dimensionalpocket/development-js (@​dimensionalpocket/development)

v1.3.0

Compare Source

Features
Bug Fixes

v1.2.0

Compare Source

Features
Bug Fixes

v1.1.0

Compare Source

Features
Bug Fixes

v1.0.2

Compare Source

Features
Bug Fixes

v1.0.1

Compare Source

Bug Fixes

v1.0.0

Compare Source

⚠ BREAKING CHANGES
  • replace version.json with version.js
Features
Bug Fixes

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/dimensionalpocket-development-1.x branch 2 times, most recently from 2cf5db5 to 6b8197d Compare August 13, 2025 16:08
@renovate renovate bot force-pushed the renovate/dimensionalpocket-development-1.x branch from 6b8197d to 50d844f Compare August 19, 2025 18:09
@renovate renovate bot force-pushed the renovate/dimensionalpocket-development-1.x branch from 50d844f to d5b2570 Compare August 31, 2025 13:15
@renovate renovate bot force-pushed the renovate/dimensionalpocket-development-1.x branch from d5b2570 to feb5347 Compare September 25, 2025 15:23
@renovate renovate bot force-pushed the renovate/dimensionalpocket-development-1.x branch from feb5347 to b4ce15d Compare October 21, 2025 10:01
@renovate renovate bot force-pushed the renovate/dimensionalpocket-development-1.x branch from b4ce15d to 7b719e1 Compare November 10, 2025 16:54
@renovate renovate bot force-pushed the renovate/dimensionalpocket-development-1.x branch from 7b719e1 to b10ba13 Compare November 18, 2025 22:50
@socket-security
Copy link

socket-security bot commented Nov 18, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​dimensionalpocket/​development@​github:dimensionalpocket/​development-js#3544c4c83496cd3477756468970bb9d18dc5c56d ⏵ github:dimensionalpocket/​development-js#f5b8263495c7064cb68d4985bebd1e9a11d93b75100100100100100

View full report

@renovate renovate bot force-pushed the renovate/dimensionalpocket-development-1.x branch from b10ba13 to 75d41d2 Compare December 3, 2025 18:49
@renovate renovate bot force-pushed the renovate/dimensionalpocket-development-1.x branch from 75d41d2 to 3fcd680 Compare December 31, 2025 15:37
@renovate renovate bot force-pushed the renovate/dimensionalpocket-development-1.x branch from 3fcd680 to 6164c6a Compare January 8, 2026 19:42
@socket-security
Copy link

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Critical
Malicious package: npm function-bind

Note: This VS Code extension is classified as malware because it exhibits high-confidence brandjacking and typosquatting indicators that strongly imply deceptive distribution and user impersonation:

  • Publisher impersonation: The VSIX claims to be “JFrog VSCode Extension,” but it is published by Artifactory-Software-Studio, not the official JFrog publisher.
  • Typosquatted identifier: The extension’s identity is vscode-jrrog-extension (note the “jrrog” typo), which is a look-alike of the official JFrog extension identifier and consistent with marketplace typosquat tactics.
  • Abuse of trust via branding: The manifest and package metadata deliberately reuse JFrog’s brand name (“JFrog VSCode Extension”) to induce installation under false provenance.
  • High-risk capability overlap: The extension’s functionality includes reading JFrog CLI configuration/credentials and initiating outbound network connections for scanning workflows. In a typosquatted/impersonating package, these capabilities materially increase the likelihood of credential theft or sensitive project metadata leakage, regardless of whether the current bundle contains overt C2 logic.

Together, the deceptive provenance (non-official publisher + typo-lookalike ID + brand reuse) is sufficient to classify the extension as malicious because it is designed to obtain installs by masquerading as a trusted vendor extension, a common precursor to credential harvesting and supply-chain compromise.

From: package-lock.jsonnpm/function-bind@1.1.2

ℹ Read more on: This package | This alert | What is known malware?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: It is strongly recommended that malware is removed from your codebase.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/function-bind@1.1.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant