Generated SDK #2850019096 (major) - #209
sdk-generation-automation[bot] merged 1 commit into
Conversation
|
Your request is important to us. We will look into it shortly. (Note that this SDK code is auto generated) |
| "resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.410.tgz", | ||
| "integrity": "sha512-Vq9DD7F4PKCKVmOoG6i1CQSYoF7IUtwTPEQjMXuqNs2S22H8HsojO9myaB81QuvvIKZaF6imSn3XAV1Su6rvXA==", | ||
| "version": "1.5.415", | ||
| "resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.415.tgz", |
There was a problem hiding this comment.
Semgrep identified an issue in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.415.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.
To resolve this comment:
✨ Commit fix suggestion
| "resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.415.tgz", | |
| "resolved": "<VERIFIED_VALUE_REQUIRED>", |
View step-by-step instructions
-
Update the project’s
.npmrcto use the approved internal JFrog/Artifactory npm registry for all packages, for exampleregistry=<approved-internal-registry-url>. Do not usehttps://registry.npmjs.orgor another public registry. -
Remove the existing dependency installation and lockfile so npm can resolve every package through the internal registry:
$ rm -rf node_modules package-lock.json -
Regenerate the dependency tree with the repository’s configured registry:
$ npm install -
Confirm that the regenerated
package-lock.jsoncontains no public npm registry or CDN URLs inresolved,registry, ortarballfields. All dependency URLs must point to the approved internal Artifactory registry. -
Keep the updated
.npmrcand regeneratedpackage-lock.jsonin the change so future installs use the approved registry.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.
You can view more details about this finding in the Semgrep AppSec Platform.
| "resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001809.tgz", | ||
| "integrity": "sha512-xxWVywk6a6Arlk+hymeycyn/VgqEfLDxupvhH/xiY5SJ/18kmi9o6MiO320DCUzypORHLtvh0I4i04tUhCNHNQ==", | ||
| "version": "1.0.30001810", | ||
| "resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001810.tgz", |
There was a problem hiding this comment.
Semgrep identified an issue in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001810.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.
To resolve this comment:
✨ Commit fix suggestion
| "resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001810.tgz", | |
| "resolved": "<VERIFIED_VALUE_REQUIRED>", |
View step-by-step instructions
- Update the project
.npmrcto use the approved internal JFrog/Artifactory npm registry, for exampleregistry=https://example.com/artifactory/api/npm/<approved-repository>/. Use the exact registry URL provided by your organization. - Configure registry authentication through your environment or approved credential helper; do not place usernames, passwords, or tokens in
.npmrcor source control. - Delete the existing dependency artifacts so npm does not retain public registry URLs:
$ rm -rf node_modules package-lock.json - Regenerate the dependency tree using the configured internal registry:
$ npm install - Confirm the regenerated
package-lock.jsoncontains Artifactory URLs forresolvedpackage tarballs, includingcaniuse-lite, rather thanhttps://registry.npmjs.org/.... - Keep the updated project
.npmrcand regeneratedpackage-lock.jsonin the change so future installs use the approved registry.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.
You can view more details about this finding in the Semgrep AppSec Platform.
| "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz", | ||
| "integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==", | ||
| "version": "1.1.20", | ||
| "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.20.tgz", |
There was a problem hiding this comment.
Semgrep identified an issue in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.20.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.
To resolve this comment:
✨ Commit fix suggestion
| "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.20.tgz", | |
| "resolved": "<VERIFIED_VALUE_REQUIRED>/brace-expansion/-/brace-expansion-1.1.20.tgz", |
View step-by-step instructions
- Configure the project
.npmrcto use the approved internal JFrog/Artifactory npm registry, replacing the placeholder with your organization’s registry URL:registry=https://example.com/artifactory/api/npm/<approved-repository>/. - Preserve any required internal authentication settings in
.npmrcor the configured credential store; do not add tokens or passwords to the repository. - Remove the existing dependency tree and lockfile:
$ rm -rf node_modules package-lock.json. - Regenerate the dependencies through the internal registry:
$ npm install. - Confirm that the regenerated
package-lock.jsonuses the approved internal registry for allresolvedpackage URLs, includingbrace-expansion,balanced-match, andbraces, rather thanregistry.npmjs.org.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.
You can view more details about this finding in the Semgrep AppSec Platform.
| "resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.15.tgz", | ||
| "integrity": "sha512-FwMjJJ7HnyZpWe+oWxegG0fezZyBZUagI5LZEoO3GCbtbKNwRfMH9Ue5d5v01PNePBy1QSfPSDTTeVL0Hb9EzA==", | ||
| "version": "2.11.19", | ||
| "resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.19.tgz", |
There was a problem hiding this comment.
Semgrep identified an issue in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.19.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.
To resolve this comment:
✨ Commit fix suggestion
| "resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.19.tgz", | |
| "resolved": "<VERIFIED_VALUE_REQUIRED>", |
View step-by-step instructions
- Add or update the project
.npmrcwith the approved JFrog/Artifactory registry:registry=https://example.com/artifactory/api/npm/<approved-repository>/. Replace the example URL with the registry URL provided by your organization. - Configure registry authentication through your environment or approved credential helper. Do not commit usernames, passwords, or tokens in
.npmrc; reference a variable such as${NPM_TOKEN}when authentication is required. - Remove the existing dependency installation and lockfile so npm does not retain public registry URLs:
$ rm -rf node_modules package-lock.json - Regenerate the dependencies using the configured internal registry:
$ npm install - Confirm the regenerated
package-lock.jsonuses the approved Artifactory host forresolvedandregistryentries, including thebaseline-browser-mappingentry. Ensure noregistry.npmjs.orgor other public registry URLs remain.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.
You can view more details about this finding in the Semgrep AppSec Platform.
Changelog
2026-09-01
Breaking Change
Fix
validBefore/validAftersemantics in TRLink policy rulesProducts: Transactions
Scope: API + SDKs
What's new
Corrects the documentation for validBefore and validAfter fields to accurately describe their behavior as relative durations (seconds since wait/screening step started) rather than absolute Unix timestamps.
Impact
Customers should update their implementations to use relative durations in seconds instead of Unix timestamps for these fields.
Affected endpoints:
Fix
validBefore/validAftersemantics in TRLink policy rulesProducts: TRLink
Scope: API + SDKs
What's new
Corrects the documentation for validBefore and validAfter fields to accurately describe their behavior as relative durations (seconds since wait/screening step started) rather than absolute Unix timestamps.
Impact
Customers should update their implementations to use relative durations in seconds instead of Unix timestamps for these fields.
Affected endpoints:
Fix
validBefore/validAftersemantics in TRLink policy rulesProducts: Compliance
Scope: API + SDKs
What's new
Corrects the documentation for validBefore and validAfter fields to accurately describe their behavior as relative durations (seconds since wait/screening step started) rather than absolute Unix timestamps.
Impact
Customers should update their implementations to use relative durations in seconds instead of Unix timestamps for these fields.
Affected endpoints:
Remove
typefield from security finding responsesProducts: Security Posture Management
Scope: API + SDKs
What's new
Removes the
typefield from security finding schemas and updates example data to reflect a different finding scenario.Impact
Clients should no longer expect the
typefield in security finding responses and must update any code that depends on this field.Affected endpoints:
Added
Add contacts list endpoint
Products: Contacts
Scope: API + SDKs
What's new
Adds a paginated endpoint to list workspace address book contacts with filtering by name, type, tags, access control, container, and archive status.
Impact
Customers can programmatically retrieve and filter their address book contacts through the API.
Affected endpoints:
Add
feeCurrencyfield for Tempo transactions (beta)Products: Off exchanges, Transactions
Scope: API + SDKs
What's new
Adds an optional
feeCurrencyfield to the transaction request schema, allowing users to specify which asset to use for paying network fees on Tempo-based transactions.Impact
Customers using Tempo can now control which asset pays transaction fees.
Affected endpoints:
Add
AMOUNT_ABOVE_MAXIMUMfailure reasonProducts: Trading (Beta)
Scope: API + SDKs
What's new
Adds a new enum value to indicate when a trading operation fails because the requested amount exceeds the maximum allowed limit.
Impact
Customers can now programmatically detect and handle amount-too-large errors in trading operations.
Affected endpoints: