Skip to content

[web] Systematize the WASM integration#10006

Merged
mnvr merged 7 commits intomainfrom
wwwasm
Apr 10, 2026
Merged

[web] Systematize the WASM integration#10006
mnvr merged 7 commits intomainfrom
wwwasm

Conversation

@mnvr
Copy link
Copy Markdown
Member

@mnvr mnvr commented Apr 10, 2026

Fixes the build

@mnvr mnvr requested a review from ua741 April 10, 2026 06:44
@mnvr mnvr deployed to workflow-security-review April 10, 2026 06:44 — with GitHub Actions Active
@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​vite@​5.2.1287658399100
Updatednpm/​eslint@​9.30.1 ⏵ 8.57.08910010050 -46100
Updatednpm/​@​typescript-eslint/​parser@​8.35.1 ⏵ 7.11.0100 +11007198100
Addednpm/​@​types/​react-datepicker@​6.2.01001007280100
Addednpm/​@​date-io/​date-fns@​3.0.01001007281100
Updatednpm/​@​types/​react-dom@​19.2.2 ⏵ 18.3.0100 +110075 +186100
Updatednpm/​prettier-plugin-packagejson@​2.5.17 ⏵ 2.5.01001007792 +3100
Updatednpm/​@​types/​react@​19.2.2 ⏵ 18.3.310010079 +190100
Updatednpm/​@​typescript-eslint/​eslint-plugin@​8.35.1 ⏵ 7.11.0991008098100
Addednpm/​date-fns@​3.6.0981009280100
Addednpm/​react-toastify@​10.0.510010010080100
Updatednpm/​prettier-plugin-organize-imports@​4.1.0 ⏵ 3.2.4100 +1100100 +181100
Addednpm/​@​emotion/​styled@​11.13.01001008285100
Updatednpm/​eslint-plugin-react@​7.37.5 ⏵ 7.34.29710010082100
Addednpm/​@​mui/​lab@​5.0.0-alpha.1739810083100100
Addednpm/​@​emotion/​react@​11.13.31001008784100
Updatednpm/​react@​19.2.0 ⏵ 18.3.110010084 +197100
Addednpm/​@​rollup/​plugin-node-resolve@​15.2.39810010085100
Addednpm/​react-datepicker@​7.5.09810010086100
Addednpm/​zod@​3.23.89710010088100
Updatednpm/​eslint-plugin-react-refresh@​0.4.20 ⏵ 0.4.710010010089100
Addednpm/​@​mui/​icons-material@​5.16.79310089100100
Addednpm/​@​mui/​material@​5.16.78910091100100
Addednpm/​typescript@​5.9.3100100909990
Addednpm/​typescript@​5.4.5100100909990
Updatednpm/​prettier@​3.6.2 ⏵ 3.3.090 +110097 +195 +5100
Updatednpm/​prettier@​3.6.2 ⏵ 3.8.2100 +11100100 +491 +1100
Updatednpm/​react-dom@​19.2.0 ⏵ 18.3.192 -71009298100
Addednpm/​wrangler@​4.81.1991009296100
Addednpm/​@​mui/​x-date-pickers@​7.22.2921009399100
Updatednpm/​eslint-plugin-react-hooks@​5.2.0 ⏵ 4.6.2100 +210093 -796100
Updatednpm/​@​vitejs/​plugin-react@​5.0.4 ⏵ 4.3.0100 +110010097 +1100
Addednpm/​@​cloudflare/​workers-types@​4.20260410.1100100100100100

View full report

@socket-security
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm vite is 92.0% likely obfuscated

Confidence: 0.92

Location: Package overview

From: infra/staff/package.jsonnpm/vite@5.2.12

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vite@5.2.12. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@mnvr mnvr merged commit 8605a9f into main Apr 10, 2026
5 checks passed
@mnvr mnvr deleted the wwwasm branch April 10, 2026 06:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant