Skip to content

Conversation

@RomanHotsiy
Copy link

@RomanHotsiy RomanHotsiy commented May 26, 2025

I also upgraded the testing library as the @testing-library/react-hooks is deprecated.

Fixes #423

A few notable changes:

  • useMemo typings in react changed so deps argument can't be undefined anymore (I updated in the code)
  • one test was giving 2 instead of 3 renders. I didn't have time to dig, @avkonst maybe you would understand it faster but if you're busy let me know, I can dig
  • updated test code in one place as the renderHook from @testing-library/react doesn't return error but throws instead

@phylum-io
Copy link

phylum-io bot commented May 26, 2025

Phylum OSS Supply Chain Risk Analysis - FAILED

This repository analyzes the risk of new dependencies. An
administrator of this repository has set requirements via Phylum policy.

If you see this comment, one or more dependencies have failed Phylum's risk analysis.

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

Eta vulnerable to Code Injection via templates rendered with user-defined data

Risk Domain: Software Vulnerability
Risk Level: high

Reason: Critical or High software vulnerability

XSS Attack with Express API

Risk Domain: Software Vulnerability
Risk Level: high

Reason: Critical or High software vulnerability

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] references suspicious URLs.

Risk Domain: Malicious Code
Risk Level: medium

Reason: Suspicious URL reference

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: @algolia/[email protected] failed.

@algolia/[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

View this project in the Phylum UI

@RomanHotsiy
Copy link
Author

The lock file is generated using pnpm 7.30.0, not sure why it breaks builds.

@RomanHotsiy
Copy link
Author

Hey @avkonst.

Would you be able to take a look at this PR this week?

@avkonst
Copy link
Owner

avkonst commented May 29, 2025

Hi, thank you for contribution. I am not able to look at this week but will try on weekend or next week. Could you please investigate what changed in the rerender from 2 to 3? That will help a lot

@RomanHotsiy
Copy link
Author

@avkonst do you need any help maybe?

@phylum-io
Copy link

phylum-io bot commented Nov 19, 2025

Phylum OSS Supply Chain Risk Analysis - FAILED

This repository analyzes the risk of new dependencies. An
administrator of this repository has set requirements via Phylum policy.

If you see this comment, one or more dependencies have failed Phylum's risk analysis.

Package: [email protected] failed.

Axios is vulnerable to DoS attack through lack of data size check

Risk Domain: Software Vulnerability
Risk Level: high

Reason: Critical or High software vulnerability

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

Eta vulnerable to Code Injection via templates rendered with user-defined data

Risk Domain: Software Vulnerability
Risk Level: high

Reason: Critical or High software vulnerability

XSS Attack with Express API

Risk Domain: Software Vulnerability
Risk Level: high

Reason: Critical or High software vulnerability

Package: [email protected] failed.

form-data uses unsafe random function in form-data for choosing boundary

Risk Domain: Software Vulnerability
Risk Level: critical

Reason: Critical or High software vulnerability

Package: [email protected] failed.

form-data uses unsafe random function in form-data for choosing boundary

Risk Domain: Software Vulnerability
Risk Level: critical

Reason: Critical or High software vulnerability

Package: [email protected] failed.

glob CLI: Command injection via -c/--cmd executes matches with shell:true

Risk Domain: Software Vulnerability
Risk Level: high

Reason: Critical or High software vulnerability

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] references suspicious URLs.

Risk Domain: Malicious Code
Risk Level: medium

Reason: Suspicious URL reference

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: [email protected] failed.

[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

Package: @algolia/[email protected] failed.

@algolia/[email protected] is decoding Base64 strings

Risk Domain: Malicious Code
Risk Level: low

Reason: Obfuscated code

View this project in the Phylum UI

@avkonst
Copy link
Owner

avkonst commented Nov 30, 2025

Hi @RomanHotsiy . Sorry for dropping the ball here, life carried over with changes and I am overloaded over the board now. If you can help that would be great. If you could investigate the remaining two tests failing, suggest a fix in PR and I will merge. If you would like to take more active role in the project. I am happy to share as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

support for React 19

3 participants