Skip to content

Chore switch to map libre#1839

Open
ErikSin wants to merge 16 commits intodevelopfrom
chore-switch-to-map-libre
Open

Chore switch to map libre#1839
ErikSin wants to merge 16 commits intodevelopfrom
chore-switch-to-map-libre

Conversation

@ErikSin
Copy link
Copy Markdown
Contributor

@ErikSin ErikSin commented Apr 16, 2026

checking tests

@awana-lockfile-bot
Copy link
Copy Markdown

package-lock.json changes

Click to toggle table visibility
Name Status Previous Current
@maplibre/maplibre-react-native ADDED - 10.4.2
@rnmapbox/maps REMOVED 10.1.42 -
@turf/along REMOVED 6.5.0 -
@turf/bearing REMOVED 6.5.0 -
@turf/destination REMOVED 6.5.0 -
@turf/length REMOVED 6.5.0 -
@turf/line-intersect REMOVED 6.5.0 -
@turf/line-segment REMOVED 6.5.0 -
@turf/nearest-point-on-line REMOVED 6.5.0 -
debounce REMOVED 1.2.1 -
geojson-rbush REMOVED 3.2.0 -

@awana-lockfile-bot
Copy link
Copy Markdown

src/backend/package-lock.json changes

Click to toggle table visibility
Name Status Previous Current
@comapeo/map-server UPDATED 1.0.1 1.1.2
@gmaclennan/zip-reader ADDED - 1.0.0
@mapbox/mapbox-gl-style-spec ADDED - 14.21.0
@mapbox/point-geometry ADDED - 1.1.0
@sqlite.org/sqlite-wasm ADDED - 3.51.2-build8
cheap-ruler ADDED - 4.0.0
csscolorparser ADDED - 1.0.3
smp-noto-glyphs ADDED - 1.0.0-pre.0
styled-map-package-api ADDED - 5.0.0-pre.4
wsl-utils REMOVED 0.1.0 -
zip-writer ADDED - 2.2.0

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​@​osm_borders/​maritime_10000m@​1.1.0501003776100
Addednpm/​@​formatjs/​cli@​6.8.2991004196100
Addednpm/​@​types/​lodash.isequal@​4.5.81001005780100
Addednpm/​@​react-native/​typescript-config@​0.76.91001006397100
Addednpm/​@​react-native/​metro-babel-transformer@​0.76.9991006597100
Addednpm/​@​types/​lint-staged@​13.3.01001006680100
Addednpm/​@​types/​react-native-zeroconf@​0.13.1971006978100
Addednpm/​@​comapeo/​nodejs-mobile-react-native@​18.20.4-26910010092100
Addednpm/​@​types/​react-native-indicators@​0.16.6891007178100
Addednpm/​@​react-native/​metro-config@​0.79.51001007297100
Addednpm/​@​tanstack/​eslint-plugin-query@​5.91.21001007497100
Addednpm/​@​types/​semver@​7.7.11001007581100
Addednpm/​@​comapeo/​core-react@​10.0.1751009198100
Addednpm/​@​react-navigation/​native-stack@​7.3.2110010075100100
Addednpm/​@​react-navigation/​native@​7.1.28991007599100
Addednpm/​@​mapeo/​mock-data@​5.0.0751009792100
Addednpm/​@​react-navigation/​bottom-tabs@​7.14.0991007699100
Addednpm/​@​comapeo/​cloud@​0.3.0761008889100
Addednpm/​@​formatjs/​intl-pluralrules@​6.2.21001007692100
Addednpm/​@​react-navigation/​stack@​7.7.2991007699100
Addednpm/​@​types/​jest@​30.0.01001007781100
Addednpm/​@​formatjs/​intl-getcanonicallocales@​3.2.11001007791100
Addednpm/​@​babel/​preset-env@​7.28.5971007795100
Addednpm/​@​types/​mocha@​10.0.101001007780100
Addednpm/​@​formatjs/​intl-locale@​5.2.11001007791100
Addednpm/​@​react-native-vector-icons/​octicons@​20.4.0781008392100
Addednpm/​@​react-native-documents/​picker@​12.0.11001007893100
Addednpm/​@​types/​react@​19.2.71001007988100
Updatednpm/​@​babel/​runtime@​7.27.1 ⏵ 7.28.41001007995100
Addednpm/​@​react-native-vector-icons/​fontisto@​12.4.0791008487100
Addednpm/​@​types/​utm@​1.1.4921008180100
Addednpm/​@​formatjs/​intl-relativetimeformat@​12.2.21001008097100
See 34 more rows in the dashboard

View full report

@socket-security
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF

CVE: GHSA-3p68-rc4w-qgx5 Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF (CRITICAL)

Affected versions: >= 1.0.0 < 1.15.0; < 0.31.0

Patched version: 1.15.0

From: package-lock.jsonnpm/@wdio/browserstack-service@9.21.0npm/axios@1.8.4

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/axios@1.8.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain

CVE: GHSA-fvcv-3m26-pcqx Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain (CRITICAL)

Affected versions: >= 1.0.0 < 1.15.0; < 0.31.0

Patched version: 1.15.0

From: package-lock.jsonnpm/@wdio/browserstack-service@9.21.0npm/axios@1.8.4

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/axios@1.8.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @browserstack/ai-sdk-node is 100.0% likely obfuscated

Confidence: 1.00

Location: Package overview

From: package-lock.jsonnpm/@wdio/browserstack-service@9.21.0npm/@browserstack/ai-sdk-node@1.5.17

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@browserstack/ai-sdk-node@1.5.17. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @react-native/debugger-frontend is 96.0% likely obfuscated

Confidence: 0.96

Location: Package overview

From: package-lock.jsonnpm/@react-native/debugger-frontend@0.81.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@react-native/debugger-frontend@0.81.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant