Skip to content

deps: periodic dependency & security updates - #223

Merged
qw-in merged 5 commits into
mainfrom
quinn/deps-examples-2026-09-23
Sep 23, 2026
Merged

qw-in merged 5 commits into
mainfrom
quinn/deps-examples-2026-09-23

Conversation

@qw-in

@qw-in qw-in commented Sep 23, 2026

Copy link
Copy Markdown
Member

periodic dependency & security updates

@arcjet-review arcjet-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Arcjet Review — 🔴 High Risk

Decision: Cannot Assess

Rationale: Review failed due to an internal error: unknown error. Escalating to human reviewers.

Review: 4bb7631a | Powered by Arcjet Review

@socket-security

socket-security Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​next@​16.3.4 ⏵ 16.3.56110090 +19970
Updatednpm/​@​anthropic-ai/​sdk@​0.117.1 ⏵ 0.126.06610092 +1100 +1100
Updatednpm/​@​react-router/​serve@​7.18.2 ⏵ 7.18.4991006796 +1100
Updatednpm/​@​react-router/​fs-routes@​7.18.2 ⏵ 7.18.41001007096 +1100
Updatednpm/​@​google/​adk@​2.0.0 ⏵ 2.1.070 -11007897100
Updatednpm/​@​anthropic-ai/​claude-agent-sdk@​0.3.234 ⏵ 0.3.273100 +110092 +110070
Updatednpm/​@​arcjet/​sensitive-info-rampart@​1.12.0 ⏵ 1.13.080 +1100100 +194 +170
Updatednpm/​@​react-router/​node@​7.18.2 ⏵ 7.18.4100 +110071 +196 +1100
Updatednpm/​@​arcjet/​react-router@​1.12.0 ⏵ 1.13.072 +110010097100
Updatednpm/​@​arcjet/​fastify@​1.12.0 ⏵ 1.13.07210010097100
Updatednpm/​@​arcjet/​sveltekit@​1.12.0 ⏵ 1.13.073 +110010097100
Updatednpm/​@​ai-sdk/​openai@​3.0.97 ⏵ 3.0.11273 +110088 +198100
Updatednpm/​@​arcjet/​nuxt@​1.12.0 ⏵ 1.13.073 +110010097100
Updatednpm/​@​ai-sdk/​react@​3.0.259 ⏵ 3.0.286991007598100
Updatednpm/​@​types/​react-dom@​19.2.4 ⏵ 19.3.0100 +110075 +192100
Updatednpm/​@​arcjet/​astro@​1.12.0 ⏵ 1.13.075 +110010097100
Updatednpm/​@​arcjet/​nest@​1.12.0 ⏵ 1.13.075 +110010097100
Updatednpm/​@​react-router/​dev@​7.18.2 ⏵ 7.18.4981007696100
Updatednpm/​@​types/​react@​19.2.18 ⏵ 19.3.01001007993100
Updatednpm/​react-router@​7.18.2 ⏵ 7.18.494 +110079 +198100
Updatednpm/​@​arcjet/​decorate@​1.12.0 ⏵ 1.13.080 +210010097100
Updatednpm/​eve@​0.38.3 ⏵ 0.56.099100100 +198 +180
Updatednpm/​@​types/​node@​26.0.0 ⏵ 22.20.3100 +110081 +196100
Updatednpm/​@​types/​node@​26.0.0 ⏵ 24.13.5100 +110081 +196100
Updatednpm/​tsx@​4.23.12 ⏵ 4.23.131001008195100
Updatednpm/​@​sveltejs/​kit@​2.70.2 ⏵ 2.70.3991008198 +3100
Updatednpm/​@​arcjet/​guard@​1.12.0 ⏵ 1.13.082 +110010096 +1100
Updatednpm/​@​astrojs/​node@​11.1.2 ⏵ 11.1.51001008297 +1100
Updatednpm/​react@​19.2.8 ⏵ 19.3.0100 +110084 +197100
Updatednpm/​workflow@​4.8.3 ⏵ 4.8.999 +110086 +199 +1100
Updatednpm/​firebase-tools@​15.27.0 ⏵ 15.30.186100100 +199 +1100
Updatednpm/​@​tanstack/​react-router@​1.170.29 ⏵ 1.170.3693 +11008798100
See 29 more rows in the dashboard

View full report

@socket-security

socket-security Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: npm @arcjet/sensitive-info-rampart under CC-BY-4.0

License: CC-BY-4.0 - The applicable license policy does not permit this license (5) (package/models/rampart/LICENSE)

From: examples/nextjs-sensitive-info/package-lock.json → npm/@arcjet/sensitive-info-rampart@1.13.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@arcjet/sensitive-info-rampart@1.13.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm @google-cloud/cloud-sql-connector in module node:net

Module: node:net

Location: Package overview

From: examples/firebase-functions/package-lock.json → npm/firebase-tools@15.30.1 → npm/@google-cloud/cloud-sql-connector@1.12.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@google-cloud/cloud-sql-connector@1.12.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm @google-cloud/cloud-sql-connector in module node:dns

Module: node:dns

Location: Package overview

From: examples/firebase-functions/package-lock.json → npm/firebase-tools@15.30.1 → npm/@google-cloud/cloud-sql-connector@1.12.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@google-cloud/cloud-sql-connector@1.12.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm @google-cloud/cloud-sql-connector in module node:tls

Module: node:tls

Location: Package overview

From: examples/firebase-functions/package-lock.json → npm/firebase-tools@15.30.1 → npm/@google-cloud/cloud-sql-connector@1.12.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@google-cloud/cloud-sql-connector@1.12.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm @google-cloud/firestore-api in module globalThis["fetch"]

Module: globalThis["fetch"]

Location: Package overview

From: examples/genkit-agent/package-lock.json → npm/genkit@1.42.0 → npm/@google-cloud/firestore-api@0.2.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@google-cloud/firestore-api@0.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm @google-cloud/sql in module globalThis["fetch"]

Module: globalThis["fetch"]

Location: Package overview

From: examples/firebase-functions/package-lock.json → npm/firebase-tools@15.30.1 → npm/@google-cloud/sql@0.25.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@google-cloud/sql@0.25.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
System shell access: npm buildcheck in module child_process

Module: child_process

Location: Package overview

From: examples/google-adk-agent/package-lock.json → npm/@google/adk@2.1.0 → npm/buildcheck@0.0.7

ℹ Read more on: This package | This alert | What is shell access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should avoid accessing the shell which can reduce portability, and make it easier for malicious shell access to be introduced.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/buildcheck@0.0.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
System shell access: npm fastify-cli in module node:child_process

Module: node:child_process

Location: Package overview

From: examples/fastify/package-lock.json → npm/fastify-cli@8.0.2

ℹ Read more on: This package | This alert | What is shell access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should avoid accessing the shell which can reduce portability, and make it easier for malicious shell access to be introduced.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/fastify-cli@8.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm jest-haste-map in module node:net

Module: node:net

Location: Package overview

From: examples/firebase-functions/package-lock.json → npm/firebase-functions-test@3.5.0 → npm/jest-haste-map@30.5.1

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jest-haste-map@30.5.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Install-time scripts: npm ssh2 during install

Install script: install

Source: node install.js

From: examples/google-adk-agent/package-lock.json → npm/@google/adk@2.1.0 → npm/ssh2@1.17.0

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ssh2@1.17.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm ssh2 in module net

Module: net

Location: Package overview

From: examples/google-adk-agent/package-lock.json → npm/@google/adk@2.1.0 → npm/ssh2@1.17.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ssh2@1.17.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm ssh2 in module dns

Module: dns

Location: Package overview

From: examples/google-adk-agent/package-lock.json → npm/@google/adk@2.1.0 → npm/ssh2@1.17.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ssh2@1.17.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm ssh2 in module http

Module: http

Location: Package overview

From: examples/google-adk-agent/package-lock.json → npm/@google/adk@2.1.0 → npm/ssh2@1.17.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ssh2@1.17.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm ssh2 in module https

Module: https

Location: Package overview

From: examples/google-adk-agent/package-lock.json → npm/@google/adk@2.1.0 → npm/ssh2@1.17.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ssh2@1.17.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm ssh2 in module tls

Module: tls

Location: Package overview

From: examples/google-adk-agent/package-lock.json → npm/@google/adk@2.1.0 → npm/ssh2@1.17.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ssh2@1.17.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm ssh2 in module globalThis["fetch"]

Module: globalThis["fetch"]

Location: Package overview

From: examples/google-adk-agent/package-lock.json → npm/@google/adk@2.1.0 → npm/ssh2@1.17.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ssh2@1.17.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
System shell access: npm ssh2 in module child_process

Module: child_process

Location: Package overview

From: examples/google-adk-agent/package-lock.json → npm/@google/adk@2.1.0 → npm/ssh2@1.17.0

ℹ Read more on: This package | This alert | What is shell access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should avoid accessing the shell which can reduce portability, and make it easier for malicious shell access to be introduced.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ssh2@1.17.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Dynamic code execution: npm ssh2

Eval Type: Function

Location: Package overview

From: examples/google-adk-agent/package-lock.json → npm/@google/adk@2.1.0 → npm/ssh2@1.17.0

ℹ Read more on: This package | This alert | What is dynamic code execution?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Avoid packages that use dynamic code execution like eval(), since this could potentially execute any code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ssh2@1.17.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Environment variable access: npm @clack/core reads ACCESSIBLE

Env Vars: ACCESSIBLE

Location: Package overview

From: examples/astro/package-lock.json → npm/astro@7.3.2 → npm/@clack/core@1.5.1

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@clack/core@1.5.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Environment variable access: npm @google-cloud/firestore-api

Location: Package overview

From: examples/genkit-agent/package-lock.json → npm/genkit@1.42.0 → npm/@google-cloud/firestore-api@0.2.0

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@google-cloud/firestore-api@0.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Environment variable access: npm @google-cloud/firestore-api

Env Vars: GOOGLE_CLOUD_UNIVERSE_DOMAIN

Location: Package overview

From: examples/genkit-agent/package-lock.json → npm/genkit@1.42.0 → npm/@google-cloud/firestore-api@0.2.0

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@google-cloud/firestore-api@0.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Environment variable access: npm @google-cloud/sql

Location: Package overview

From: examples/firebase-functions/package-lock.json → npm/firebase-tools@15.30.1 → npm/@google-cloud/sql@0.25.0

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@google-cloud/sql@0.25.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Environment variable access: npm @google-cloud/sql

Env Vars: GOOGLE_CLOUD_UNIVERSE_DOMAIN

Location: Package overview

From: examples/firebase-functions/package-lock.json → npm/firebase-tools@15.30.1 → npm/@google-cloud/sql@0.25.0

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@google-cloud/sql@0.25.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Debug access: npm @nestjs/common in module module

Module: module

Location: Package overview

From: examples/nextjs-ai-agent/package-lock.json → npm/workflow@4.8.9 → npm/@nestjs/common@12.0.3

ℹ Read more on: This package | This alert | What is debug access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Removing the use of debug will reduce the risk of any reflection and dynamic code execution.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@nestjs/common@12.0.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Minified code present: npm @vercel/cli-config with 100.0% likelihood

Confidence: 1.00

Location: Package overview

From: examples/nextjs-ai-agent/package-lock.json → npm/workflow@4.8.9 → npm/@vercel/cli-config@0.2.7

ℹ Read more on: This package | This alert | What's wrong with minified code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: In many cases minified code is harmless, however minified code can be used to hide a supply chain attack. Consider not shipping minified code on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@vercel/cli-config@0.2.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

See 16 more rows in the dashboard

Ignoring alerts on:

  • npm/@parcel/watcher@2.6.0
  • npm/cpu-features@0.0.10
  • npm/docker-modem@5.0.7
  • npm/node-addon-api@7.1.1
  • npm/vite@8.3.0
  • npm/@anthropic-ai/sdk@0.126.0
  • npm/@arcjet/guard@1.13.0
  • npm/zod@4.6.5
  • npm/next@16.3.5
  • npm/react-dom@19.3.0
  • npm/@smithy/core@3.34.1
  • npm/@strands-agents/sdk@1.18.0
  • npm/@fastify/fast-json-stringify-compiler@5.1.0
  • npm/@fastify/proxy-addr@5.1.1
  • npm/fastify@5.12.5
  • npm/pino@10.3.1
  • npm/prettier@3.9.7
  • npm/thread-stream@4.2.0
  • npm/tsx@4.23.13
  • npm/@workflow/core@4.8.9
  • npm/@workflow/nest@4.0.25
  • npm/piscina@4.9.4
  • npm/undici@6.28.1
  • npm/es-module-lexer@2.3.2
  • npm/rollup@4.63.3
  • npm/env-runner@0.2.3
  • npm/eve@0.56.0
  • npm/nitro@3.0.260903-beta
  • npm/@tanstack/react-router@1.170.36
  • npm/seroval@1.6.7
  • npm/@astrojs/compiler-binding@0.4.1
  • npm/@astrojs/compiler-binding-wasm32-wasi@0.4.1
  • npm/@napi-rs/wasm-runtime@1.2.4
  • npm/@tybys/wasm-util@0.10.4
  • npm/@genkit-ai/core@1.42.0
  • npm/@genkit-ai/firebase@1.42.0
  • npm/gaxios@8.1.0
  • npm/google-auth-library@11.1.0
  • npm/googleapis-common@9.1.0
  • npm/@google/adk@2.1.0
  • npm/@mikro-orm/core@7.2.0
  • npm/@jest/snapshot-utils@30.5.1
  • npm/firebase-functions@7.4.0
  • npm/firebase-tools@15.30.1
  • npm/node-gyp@13.0.2
  • npm/@vue/language-core@3.3.11
  • npm/vue@3.5.42
  • npm/playwright-core@1.63.0
  • npm/@sveltejs/kit@2.70.3
  • npm/@openai/agents-core@0.18.0

View full report

qw-in commented Sep 23, 2026 •

Copy link
Copy Markdown
Member Author

@SocketSecurity ignore npm/@anthropic-ai/sdk@0.126.0
The flagged npx/.tgz execution path is not present in the installed SDK source or this example. The example uses the official Anthropic client API.

@SocketSecurity ignore npm/@fastify/proxy-addr@5.1.1
This is Fastify's proxy-address parser; 5.1.1 is the fixed release for GHSA-8cmm-mhw6-v7xq. The report's generic loader signal does not identify an exposed path here.

@SocketSecurity ignore npm/@google/adk@2.1.0
The example registers only its static order-lookup FunctionTool. It does not use the flagged code executor, RAG memory, or debug surfaces.

@SocketSecurity ignore npm/@jest/snapshot-utils@30.5.1
This is nested under dev-only firebase-functions-test; the example defines no test script and does not import/use that test package.

@SocketSecurity ignore npm/@parcel/watcher@2.6.0
This is an optional native file-watcher under unused Firebase test/Nest/Astro tooling; the example does not invoke those tools or watcher paths.

@SocketSecurity ignore npm/@strands-agents/sdk@1.18.0
The example supplies only two local custom tools (lookupOrder and notifyWarehouse); it does not register or invoke a shell/Bash tool.

@SocketSecurity ignore npm/@sveltejs/kit@2.70.3
GHSA-29g2-3rmr-qm68 is fixed in 2.70.2; this example pins 2.70.3, so the reported potential vulnerability is already patched.

@SocketSecurity ignore npm/@workflow/core@4.8.9
The example accepts a bounded string question and passes a plain {question, ctx} workflow input. No caller-supplied executable object reaches workflow revival.

@SocketSecurity ignore npm/cpu-features@0.0.10
This is an optional platform-detection package nested under Google ADK. The example uses a static local FunctionTool and does not invoke CPU-specific native functionality.

@SocketSecurity ignore npm/es-module-lexer@2.3.2
No published advisory is identified for this version; it only lexes module syntax. Here it is nested in unused dev-only Firebase test → Nest/Astro tooling.

@SocketSecurity ignore npm/eve@0.56.0
The Eve example defines its agent/config in local TypeScript and passes webhook text as conversation input; it does not parse caller-supplied YAML/front matter or enable YAML function tags.

@SocketSecurity ignore npm/firebase-tools@15.30.1
This example invokes only Firebase functions deploy/emulator/serve; the package-level AI and potential-vulnerability alerts identify no reachable path in those scripts. Separate audit findings remain held: GHSA-528h-pc64-c93x is under CLI DB-import/Next/auth-import paths, and GHSA-87mf-gv2c-c62c comes through unused devDependency firebase-functions-test; this ignore does not waive either transitive advisory.

@SocketSecurity ignore npm/next@16.3.5
GHSA-vcvr-r3jv-pc5j applies only to Node next/og ImageResponse with attacker-controlled SVG values. Repo-wide source search found no next/og, ImageResponse, or OG image routes in the examples.

@SocketSecurity ignore npm/nitro@3.0.260903-beta
The flagged shell call is in Nitro's optional docs CLI command. The Eve example runs eve build/dev/start and does not expose or invoke that command from request input.

@SocketSecurity ignore npm/playwright-core@1.63.0
The flagged Windows installer uses a hardcoded official dl.google.com Chrome URL; playwright-core is dev-only under @playwright/test and the example invokes only playwright test in CI, not the installer.

@SocketSecurity ignore npm/react-dom@19.3.0
The flagged static.node.js/native binding is an official React DOM static-renderer export shipped in the package tarball; this example does not import react-dom/static or fetch an external binary.

@SocketSecurity ignore npm/rollup@4.63.3
The dynamic config/plugin execution is limited to Vite's checked-in local config, which imports the fixed React Router plugin. No untrusted plugin configuration reaches Rollup.

@SocketSecurity ignore npm/seroval@1.6.7
TanStack Start's server-function handler decodes HTTP JSON with seroval.fromJSON; the eval-based deserialize(source) API has no call site in the installed Start client/server core packages.

@SocketSecurity ignore npm/tsx@4.23.13
The example uses tsx only as a dev CLI to run its trusted src/serve.ts entry point; its REPL eval code is not reachable from the application routes.

@SocketSecurity ignore npm/@arcjet/guard@1.13.0
Genkit's flagged reflection server binds to 127.0.0.1 by default; this example does not set GENKIT_REFLECTION_HOST. Its public /api/agent handler is separate and documented as a local demo, not a production auth pattern.

@SocketSecurity ignore npm/@astrojs/compiler-binding-wasm32-wasi@0.4.1
This is Astro's compiler fallback for local build/dev source compilation; its bundled WASM worker is not selected from HTTP input. The example does not set NAPI_RS_FORCE_WASI.

@SocketSecurity ignore npm/@astrojs/compiler-binding@0.4.1
The flagged pnpm install-and-require path runs only in a WebContainer when no native binding loads. The example's ordinary Node build/dev path does not set a WebContainer runtime.

@SocketSecurity ignore npm/node-gyp@13.0.2
Both medium rows have no advisory/CVE/API in the report; OSV's exact npm-version query returns no record. This is native-addon build tooling under dev-only Firebase CLI/re2, with no example runtime import.

@SocketSecurity ignore npm/@fastify/fast-json-stringify-compiler@5.1.0
Fastify compiles fixed, developer-authored route schemas into serializers; no request-controlled schema reaches the compiler.

@SocketSecurity ignore npm/@genkit-ai/core@1.42.0
This is Genkit's development reflection server; its default bind is loopback and the example does not set GENKIT_REFLECTION_HOST.

@SocketSecurity ignore npm/@genkit-ai/firebase@1.42.0
Both alerts concern opt-in Firebase auth/debug behavior. The example neither imports this plugin nor configures Firebase debug flags.

@SocketSecurity ignore npm/@mikro-orm/core@7.2.0
This is an unused transitive Google ADK ORM dependency; the example uses in-memory sessions and a local FunctionTool, with no ORM/database path.

@SocketSecurity ignore npm/@napi-rs/wasm-runtime@1.2.4
This is nested under unused dev-only firebase-functions-test → Astro compiler tooling; no application code imports or invokes that test/build path.

@SocketSecurity ignore npm/@openai/agents-core@0.18.0
The example registers only local FunctionTools; it does not configure the package's Python execvpe helper or a code-interpreter tool.

@SocketSecurity ignore npm/@smithy/core@3.34.1
This is nested under unused Strands/AWS workflow dependencies; the example does not import Strands, AWS clients, or event-stream handlers.

@SocketSecurity ignore npm/@tanstack/react-router@1.170.36
The flagged Scripts component renders framework-generated hydration scripts; repo usage supplies no attacker-controlled script source or HTML.

@SocketSecurity ignore npm/@tybys/wasm-util@0.10.4
This is nested under unused dev-only Firebase test → Astro compiler tooling; no application code imports or invokes that path.

@SocketSecurity ignore npm/@vue/language-core@3.3.11
The flagged dynamic plugin loading is confined to vue-tsc typechecking with the checked-in Nuxt project config, not application request handling.

@SocketSecurity ignore npm/@workflow/nest@4.0.25
The app uses workflow/next; no Nest adapter or Nest application is imported or configured.

@SocketSecurity ignore npm/docker-modem@5.0.7
This transitive Google ADK dependency is unused; the example uses in-memory sessions and a local FunctionTool, with no Docker client path.

@SocketSecurity ignore npm/env-runner@0.2.3
Eve's example runs its trusted local TypeScript app commands; it does not pass request data to the Deno process runner or invoke arbitrary programs.

@SocketSecurity ignore npm/fastify@5.12.5
The flagged config generator compiles fixed, checked-in route schema/default options; no user-controlled schema or compiler input is exposed.

@SocketSecurity ignore npm/firebase-functions@7.4.0
The token-verification bypass is gated by Firebase emulator debug flags; this example does not set FIREBASE_DEBUG_MODE or FIREBASE_DEBUG_FEATURES.

@SocketSecurity ignore npm/gaxios@8.1.0
The flagged Express/Karma harness lives under gaxios browser-test tooling and is not part of the public request client or the example's runtime path.

@SocketSecurity ignore npm/google-auth-library@11.1.0
The reported executable credential provider is an opt-in auth mode; the Genkit example configures no executable provider, envMap, or output-file cache. Its shown ID-token client path is standard Google auth.

@SocketSecurity ignore npm/googleapis-common@9.1.0
This is nested under dev-only Firebase CLI; the example invokes Firebase functions deploy/emulator/serve and does not expose discovery URLs or schema file paths to request input.

@SocketSecurity ignore npm/node-addon-api@7.1.1
This is under unused dev-only firebase-functions-test; the flagged clang-format helper is a developer formatting script, not application code.

@SocketSecurity ignore npm/pino@10.3.1
Fastify enables its default logger only; the example configures no dynamic transport/module path that could reach Pino's transport loader.

@SocketSecurity ignore npm/piscina@4.9.4
Both alerts are workflow worker internals. The app registers a checked-in workflow and passes user text as data; no caller-controlled worker filename or code is supplied.

@SocketSecurity ignore npm/prettier@3.9.7
Prettier is a development-only formatter with a fixed checked-in Astro plugin configuration; no application request can choose plugin identifiers or file paths.

@SocketSecurity ignore npm/thread-stream@4.2.0
Fastify/Pino uses the default stdout logger and configures no worker transport filename; the flagged module loader has no app-supplied path.

@SocketSecurity ignore npm/undici@6.28.1
All four rows are under dev-only firebase-tools. The described cache, protocol, and response helpers are standard Undici code; the file-rewriting note identifies no reachable example path.

@SocketSecurity ignore npm/vite@8.3.0
Vite's module runner is used by the Astro example's local build/dev tooling with checked-in config; no app request can provide module code or specifiers.

@SocketSecurity ignore npm/vue@3.5.42
Nuxt compiles the repository's checked-in Vue SFC templates; no route compiles user-supplied templates or exposes the runtime compiler to request data.

@SocketSecurity ignore npm/zod@4.6.5
The flagged code generator operates on schemas defined in repository code. Examples use fixed Zod schemas to validate request data; request strings are not compiled as schemas or executable code.

@arcjet-review arcjet-review Bot added the ready Ready to merge label Sep 23, 2026
@qw-in
qw-in added this pull request to the merge queue Sep 23, 2026
Merged via the queue into main with commit 2ceffe0 Sep 23, 2026
23 checks passed
@arcjet-review arcjet-review Bot removed the ready Ready to merge label Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants