Skip to content

Commit 0cf0d3f

Browse files
BlackHole1fengmk2
andauthored
feat: add @ctrl/tinycolor and 40+ packages (#277)
Ref: https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated dependency security metadata to mark specific vulnerable package versions per recent advisories across multiple ecosystems. * Improves vulnerability tracking and future dependency hygiene; no functional, UI, API, or performance changes. * No user action required. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Kevin Cui <[email protected]> Co-authored-by: MK (fengmk2) <[email protected]>
1 parent 186583f commit 0cf0d3f

File tree

1 file changed

+248
-0
lines changed

1 file changed

+248
-0
lines changed

package.json

Lines changed: 248 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1384,6 +1384,254 @@
13841384
"version": "4.1.0",
13851385
"reason": "https://github.com/debug-js/debug/issues/1005"
13861386
}
1387+
},
1388+
"angulartics2": {
1389+
"14.1.2": {
1390+
"version": "14.1.0",
1391+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1392+
}
1393+
},
1394+
"@ctrl/deluge": {
1395+
"7.2.2": {
1396+
"version": "7.2.0",
1397+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1398+
}
1399+
},
1400+
"@ctrl/golang-template": {
1401+
"1.4.3": {
1402+
"version": "1.4.1",
1403+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1404+
}
1405+
},
1406+
"@ctrl/magnet-link": {
1407+
"4.0.4": {
1408+
"version": "4.0.2",
1409+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1410+
}
1411+
},
1412+
"@ctrl/ngx-codemirror": {
1413+
"7.0.2": {
1414+
"version": "7.0.0",
1415+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1416+
}
1417+
},
1418+
"@ctrl/ngx-csv": {
1419+
"6.0.2": {
1420+
"version": "6.0.0",
1421+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1422+
}
1423+
},
1424+
"@ctrl/ngx-emoji-mart": {
1425+
"9.2.2": {
1426+
"version": "9.2.0",
1427+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1428+
}
1429+
},
1430+
"@ctrl/ngx-rightclick": {
1431+
"4.0.2": {
1432+
"version": "4.0.0",
1433+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1434+
}
1435+
},
1436+
"@ctrl/qbittorrent": {
1437+
"9.7.2": {
1438+
"version": "9.7.0",
1439+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1440+
}
1441+
},
1442+
"@ctrl/react-adsense": {
1443+
"2.0.2": {
1444+
"version": "2.0.0",
1445+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1446+
}
1447+
},
1448+
"@ctrl/shared-torrent": {
1449+
"6.3.2": {
1450+
"version": "6.3.0",
1451+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1452+
}
1453+
},
1454+
"@ctrl/tinycolor": {
1455+
"4.1.1": {
1456+
"version": "4.1.0",
1457+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1458+
},
1459+
"4.1.2": {
1460+
"version": "4.1.0",
1461+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1462+
}
1463+
},
1464+
"@ctrl/torrent-file": {
1465+
"4.1.2": {
1466+
"version": "4.1.0",
1467+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1468+
}
1469+
},
1470+
"@ctrl/transmission": {
1471+
"7.3.1": {
1472+
"version": "7.3.0",
1473+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1474+
}
1475+
},
1476+
"@ctrl/ts-base32": {
1477+
"4.0.2": {
1478+
"version": "4.0.0",
1479+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1480+
}
1481+
},
1482+
"encounter-playground": {
1483+
"0.0.5": {
1484+
"version": "0.0.4",
1485+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1486+
}
1487+
},
1488+
"json-rules-engine-simplified": {
1489+
"0.2.1": {
1490+
"version": "0.2.0",
1491+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1492+
},
1493+
"0.2.2": {
1494+
"version": "0.2.0",
1495+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1496+
},
1497+
"0.2.3": {
1498+
"version": "0.2.0",
1499+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1500+
},
1501+
"0.2.4": {
1502+
"version": "0.2.0",
1503+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1504+
}
1505+
},
1506+
"koa2-swagger-ui": {
1507+
"5.11.1": {
1508+
"version": "5.11.0",
1509+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1510+
},
1511+
"5.11.2": {
1512+
"version": "5.11.0",
1513+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1514+
}
1515+
},
1516+
"@nativescript-community/gesturehandler": {
1517+
"2.0.35": {
1518+
"version": "2.0.34",
1519+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1520+
}
1521+
},
1522+
"@nativescript-community/sentry": {
1523+
"4.6.43": {
1524+
"version": "4.6.42",
1525+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1526+
}
1527+
},
1528+
"@nativescript-community/text": {
1529+
"1.6.13": {
1530+
"version": "1.6.8",
1531+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1532+
}
1533+
},
1534+
"@nativescript-community/ui-collectionview": {
1535+
"6.0.6": {
1536+
"version": "6.0.5",
1537+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1538+
}
1539+
},
1540+
"@nativescript-community/ui-drawer": {
1541+
"0.1.30": {
1542+
"version": "0.1.29",
1543+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1544+
}
1545+
},
1546+
"@nativescript-community/ui-image": {
1547+
"4.5.6": {
1548+
"version": "4.5.5",
1549+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1550+
}
1551+
},
1552+
"@nativescript-community/ui-material-bottomsheet": {
1553+
"7.2.72": {
1554+
"version": "7.2.71",
1555+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1556+
}
1557+
},
1558+
"@nativescript-community/ui-material-core": {
1559+
"7.2.76": {
1560+
"version": "7.2.71",
1561+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1562+
}
1563+
},
1564+
"@nativescript-community/ui-material-core-tabs": {
1565+
"7.2.76": {
1566+
"version": "7.2.71",
1567+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1568+
}
1569+
},
1570+
"ngx-color": {
1571+
"10.0.2": {
1572+
"version": "10.0.0",
1573+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1574+
}
1575+
},
1576+
"ngx-toastr": {
1577+
"19.0.2": {
1578+
"version": "19.0.0",
1579+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1580+
}
1581+
},
1582+
"ngx-trend": {
1583+
"8.0.1": {
1584+
"version": "8.0.0",
1585+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1586+
}
1587+
},
1588+
"react-complaint-image": {
1589+
"0.0.35": {
1590+
"version": "0.0.34",
1591+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1592+
}
1593+
},
1594+
"react-jsonschema-form-conditionals": {
1595+
"0.3.21": {
1596+
"version": "0.3.20",
1597+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1598+
}
1599+
},
1600+
"react-jsonschema-form-extras": {
1601+
"1.0.4": {
1602+
"version": "1.0.3",
1603+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1604+
}
1605+
},
1606+
"rxnt-authentication": {
1607+
"0.0.6": {
1608+
"version": "0.0.5",
1609+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1610+
}
1611+
},
1612+
"rxnt-healthchecks-nestjs": {
1613+
"1.0.5": {
1614+
"version": "1.0.4",
1615+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1616+
}
1617+
},
1618+
"rxnt-kue": {
1619+
"1.0.7": {
1620+
"version": "1.0.6",
1621+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1622+
}
1623+
},
1624+
"swc-plugin-component-annotate": {
1625+
"1.9.2": {
1626+
"version": "1.9.0",
1627+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1628+
}
1629+
},
1630+
"ts-gaussian": {
1631+
"3.0.6": {
1632+
"version": "3.0.4",
1633+
"reason": "https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"
1634+
}
13871635
}
13881636
}
13891637
}

0 commit comments

Comments
 (0)