Repository navigation
Generated SDK #2917861426 (major) - #212
sdk-generation-automation[bot] merged 1 commit into
Conversation
|
Thanks for submitting this request. We'll review it and provide updates soon. (Note that this SDK code is auto generated) |
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
| "resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.3.2.tgz", | ||
| "integrity": "sha512-UQ+MSxlhRm1bzjhU+DcuXfjFO1FzNtqhK5+9Yvlp90ItDLk5vT932A0rFu619nf7RVS+Y/VeaUW1jaRDqZ8VJw==", | ||
| "version": "1.3.3", | ||
| "resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.3.3.tgz", |
There was a problem hiding this comment.
🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.3.3.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.
To resolve this comment:
✨ Commit fix suggestion
| "resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.3.3.tgz", | |
| "resolved": "https://fbinfra555artifactory.jfrog.io/artifactory/api/npm/fireblocks-npm/update-browserslist-db/-/update-browserslist-db-1.3.3.tgz", |
View step-by-step instructions
- Configure the project
.npmrcto use the approved internal Artifactory registry:registry=https://fbinfra555artifactory.jfrog.io/artifactory/api/npm/fireblocks-npm/. - Configure authentication through your approved npm credential mechanism, such as an environment variable or user-level npm configuration; do not store tokens in the repository.
- Remove the existing dependency artifacts so npm does not preserve public registry URLs:
$ rm -rf node_modules package-lock.json. - Regenerate the dependency tree through Artifactory:
$ npm install. - Confirm the regenerated
package-lock.jsonresolvesupdate-browserslist-dband all other packages through the approved Artifactory URL rather thanregistry.npmjs.org.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.
You can view more details about this finding in the Semgrep AppSec Platform.
There was a problem hiding this comment.
SocketSecurity ignore npm/update-browserslist-db@1.3.3
| "resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.425.tgz", | ||
| "integrity": "sha512-QvPtl41EUOnuT1HBvMKgxXRIaHNcagBPs50u7VULzhZXaGfqTbZyE16LQsctZ/RQHlGu+FOWeDTR4mY6YbeF1g==", | ||
| "version": "1.5.429", | ||
| "resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.429.tgz", |
There was a problem hiding this comment.
🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.429.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.
To resolve this comment:
✨ Commit fix suggestion
| "resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.429.tgz", | |
| "resolved": "<VERIFIED_VALUE_REQUIRED>", |
View step-by-step instructions
- Create or update the project
.npmrcwith the approved internal Artifactory registry, replacing the example URL with the exact URL provided by your organization:registry=https://example.com/artifactory/api/npm/npm-virtual/. - Configure Artifactory authentication through your approved credential helper, environment variables, or user-level npm configuration. Do not commit access tokens or passwords to
.npmrc. - Remove the existing dependency artifacts so npm does not preserve public registry URLs:
$ rm -rf node_modules package-lock.json. - Regenerate the dependency tree using the configured registry:
$ npm install. - Confirm that
package-lock.jsonnow contains Artifactory URLs forresolvedpackage entries, includingelectron-to-chromium, and no longer referenceshttps://registry.npmjs.org/or another public registry.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.
You can view more details about this finding in the Semgrep AppSec Platform.
There was a problem hiding this comment.
@SocketSecurity ignore npm/electron-to-chromium@1.5.429
| "resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.28.9.tgz", | ||
| "integrity": "sha512-EWazOblFYUvlGZcfGhPUPmYh3nikUxBVb+y9MJun5f3hBi812X+8MSQTujLBtgK3cf51fJWbWfOjyeO954d+Eg==", | ||
| "version": "4.29.0", | ||
| "resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.29.0.tgz", |
There was a problem hiding this comment.
🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/browserslist/-/browserslist-4.29.0.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.
To resolve this comment:
✨ Commit fix suggestion
| "resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.29.0.tgz", | |
| "resolved": "https://<VERIFIED_VALUE_REQUIRED>/artifactory/api/npm/<VERIFIED_VALUE_REQUIRED>/browserslist/-/browserslist-4.29.0.tgz", |
View step-by-step instructions
- Configure the project’s
.npmrcto use the approved internal JFrog/Artifactory npm registry, for exampleregistry=https://example.com/artifactory/api/npm/<approved-repository>/. - Remove the existing dependency artifacts so npm does not reuse public registry URLs:
$ rm -rf node_modules package-lock.json. - Regenerate the dependency lockfile with the internal registry configured:
$ npm install. - Confirm the
resolvedentry forbrowserslistuses the approved internal Artifactory host instead ofhttps://registry.npmjs.org, while preserving the package version and integrity value. Regenerating the lockfile updates transitive dependencies in the same way.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.
You can view more details about this finding in the Semgrep AppSec Platform.
| "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.20.tgz", | ||
| "integrity": "sha512-5/qk29RyvatwgzNMrvGjkIhKYzpJ0OUnPK+9TU+zS/CMJqzmb+UD0irWu42JfpUvO636fxd8IstgiydZRM/76A==", | ||
| "version": "1.1.21", | ||
| "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.21.tgz", |
There was a problem hiding this comment.
🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.21.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.
To resolve this comment:
✨ Commit fix suggestion
| "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.21.tgz", | |
| "resolved": "<VERIFIED_VALUE_REQUIRED>", |
View step-by-step instructions
- Set the project registry in
.npmrcto the approved internal JFrog/Artifactory npm registry, for exampleregistry=https://example.com/artifactory/api/npm/npm-virtual/. Use the exact registry URL provided by your organization. - Configure registry authentication through your standard credential mechanism, such as
npm loginor an environment variable; do not add tokens or passwords to.npmrccommitted to the repository. - Remove the existing dependency installation and lockfile:
$ rm -rf node_modules package-lock.json - Regenerate both from the internal registry:
$ npm install - Confirm that
package-lock.jsoncontainsresolvedURLs for the approved internal registry instead of public hosts such asregistry.npmjs.org.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.
You can view more details about this finding in the Semgrep AppSec Platform.
There was a problem hiding this comment.
SocketSecurity ignore npm/brace-expansion@1.1.21
| "resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.21.tgz", | ||
| "integrity": "sha512-uh8vpY/1/YyFkunIDFH/12p7/7VdPKA1hejMVEbdkEaWnUz0Hesvx5EbiU6XxjyHZIOju+ZMbQJkRh+es3/spQ==", | ||
| "version": "2.11.24", | ||
| "resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.24.tgz", |
There was a problem hiding this comment.
🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.24.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.
To resolve this comment:
✨ Commit fix suggestion
| "resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.24.tgz", | |
| "resolved": "<VERIFIED_VALUE_REQUIRED>/baseline-browser-mapping/-/baseline-browser-mapping-2.11.24.tgz", |
View step-by-step instructions
- Update
.npmrcto use the approved internal JFrog/Artifactory npm registry, for exampleregistry=<approved-internal-artifactory-npm-endpoint>. Configure authentication through the existing secure npm or CI mechanism; do not commit credentials. - Remove the existing dependency installation and lockfile with
$ rm -rf node_modules package-lock.json. - Regenerate the lockfile through the internal registry with
$ npm install. - Confirm the regenerated
package-lock.jsonuses the approved internal Artifactory URL forbaseline-browser-mappingand its transitive dependencies instead ofregistry.npmjs.org. The existing integrity hashes continue to verify the downloaded package contents.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.
You can view more details about this finding in the Semgrep AppSec Platform.
There was a problem hiding this comment.
@SocketSecurity ignore npm/baseline-browser-mapping@2.11.24
Changelog
2026-10-06
Breaking Change
Group Tempo transfers under Tempo (Beta)
Products: Tempo (Beta)
Scope: API + SDKs
What's new
Tempo transfer operations are now grouped under a dedicated Tempo (Beta) product category instead of being listed with Transactions (Beta).
Impact
SDK users will find Tempo transfers on a dedicated Tempo client rather than the transactions client, while direct API calls are unaffected.
Affected endpoints:
Transfer withdraw moves to offer responses
Products: Canton (Beta)
Scope: API + SDKs
What's new
Withdrawing a Canton transfer is now done by answering the offer instead of submitting a Canton call.
Impact
Existing integrations that withdraw Canton transfers through the calls endpoint will stop working.
Affected endpoints:
Canton call payloads now use
blockchainIdProducts: Canton (Beta)
Scope: API + SDKs
What's new
Canton call payloads now identify the chain with a required
blockchainIdfield in place ofasset.Impact
Existing integrations sending
asseton Canton calls will receive a validation error.Affected endpoints:
Simplify Canton offer response format (beta)
Products: Canton (Beta)
Scope: API + SDKs
What's new
Answering a Canton offer now takes a single response type plus its arguments, instead of nesting the response inside a domain wrapper.
Impact
Existing integrations that answer Canton offers will be rejected until they send the new body shape.
Affected endpoints:
Approval API keys support pending approval state
Products: Approvals (Beta)
Scope: API + SDKs
What's new
Registering or removing an approval API key can now require approval, and each key now reports a
statusof pending registration, enabled, or pending deletion.Impact
Integrations that manage approval API keys must handle keys that are awaiting approval, and the key removal response now returns a body identifying the pending approval request.
Affected endpoints:
Added
Add Tempo omnibus wallet registration
Products: Vaults
Scope: API + SDKs
What's new
Adds a new endpoint that registers a Tempo omnibus wallet for a given vault account and Tempo network asset.
Impact
Customers can now register Tempo omnibus wallets programmatically; this is an additive change, so existing integrations continue to work unchanged.
Affected endpoints:
Changed
Document gas funding for Tempo omnibus
Products: Vaults
Scope: API + SDKs
What's new
Tempo omnibus wallet registration now documents that the vault account must hold a
PATH_USDbalance sufficient to cover the gas fee.Impact
Customers know upfront that the vault account needs funded gas before registration can succeed, avoiding unexpected failures.
Affected endpoints:
Clarify console user deletion errors (beta)
Products: Console User
Scope: API + SDKs
What's new
Deleting a console user now returns a distinct bad-request error when the supplied ID belongs to an API user rather than a console user, and Security Admin keys are now permitted to perform the deletion.
Impact
Customers targeting the wrong user type receive a clear failure reason instead of a not-found response, and workspaces using Security Admin keys can now delete console users.
Affected endpoints: