Skip to content

Comments

(Test) Socket should report that bowserify is malicious / typosquat attack#13

Open
njsfield wants to merge 1 commit intomasterfrom
install-bowserify-test
Open

(Test) Socket should report that bowserify is malicious / typosquat attack#13
njsfield wants to merge 1 commit intomasterfrom
install-bowserify-test

Conversation

@njsfield
Copy link
Owner

@njsfield njsfield commented Feb 5, 2023

Assert that Socket fails PR checks and reports that bowserify is a typosquat package, attempting to pose as browserify

@socket-security
Copy link

socket-security bot commented Feb 5, 2023

Socket Security Pull Request Report

👍 No new dependency issues detected in pull request

Pull request report summary
Issue Status
Install scripts ✅ 0 issues
Native code ✅ 0 issues
Bin script confusion ✅ 0 issues
Bin script shell injection ✅ 0 issues
Unresolved require ✅ 0 issues
Invalid package.json ✅ 0 issues
HTTP dependency ✅ 0 issues
Git dependency ✅ 0 issues
Potential typo squat ✅ 0 issues
Known Malware ✅ 0 issues
Telemetry ✅ 0 issues
Protestware/Troll package ✅ 0 issues
Bot Commands

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@2.4.2

Ignoring: bowserify@10.2.1

Powered by socket.dev

@njsfield
Copy link
Owner Author

njsfield commented Feb 5, 2023

@SocketSecurity ignore bowserify@10.2.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant