Skip to content

chore: move create-release-branch to packages - #35

Merged
GuillaumeRx merged 2 commits into
mainfrom
gr/crb-move
Oct 9, 2026
Merged

GuillaumeRx merged 2 commits into
mainfrom
gr/crb-move

Conversation

@GuillaumeRx

@GuillaumeRx GuillaumeRx commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Explanation

Move @metamask/create-release-branch from merged-packages/ to packages/ and register it as a regular workspace.

This PR contains the directory move and the required root configuration updates only. The package files are preserved as renames from the previous fixes PR.

The merged-packages handling in .gitignore, the lint configuration, and the security-scanner workflow paths is kept, since the folder may hold other packages in the future. The new package gets its own lint and knip configuration instead:

  • Oxlint keeps ignoring merged-packages/** and gains overrides scoped to packages/create-release-branch (Node.js environment, browser environment for the Vite UI).
  • knip ignores react-markdown and tailwindcss for this workspace because it cannot see the Vite-built UI usage.

The release build continues to compile the package and build its Vite UI before publishing the package's dist/ artifacts.

References

  • Follows the fixes PR.

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

@socket-security

socket-security Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Warning

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Priority Alert  (click "▶" to expand/collapse) Action
Low priority
Environment variable access: npm @babel/code-frame reads FORCE_COLOR

Env Vars: FORCE_COLOR

Location: Package overview

From: packages/create-release-branch/package.json → npm/@vitejs/plugin-react@4.7.0 → npm/@babel/code-frame@7.29.7

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/code-frame@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @babel/core is 68.0% likely to have a medium risk anomaly

Notes: The code defines a stack-trace manipulation utility that can selectively hide or reveal frames and inject synthetic frames into error traces. While not inherently malicious, its global alteration of Error.prepareStackTrace and stackTraceLimit enables obfuscation of error reporting and can hinder debugging or auditing. Use is advised with thorough documentation and restricted scope in security-sensitive environments.

Confidence: 0.68

Severity: 0.60

From: packages/create-release-branch/package.json → npm/@vitejs/plugin-react@4.7.0 → npm/@babel/core@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/core@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @babel/core is 75.0% likely to have a medium risk anomaly

Notes: The examined code is a standard, benign helper for constructing and wrapping configuration items from descriptors within Babel’s tooling. There is no evidence of data leakage, exfiltration, backdoors, or other malicious activity in this fragment. The combination of immutability, brand-based identity, and non-enumerable descriptor storage indicates a well-scoped internal utility rather than anything suspicious.

Confidence: 0.75

Severity: 0.50

From: packages/create-release-branch/package.json → npm/@vitejs/plugin-react@4.7.0 → npm/@babel/core@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/core@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @babel/helper-module-imports is 78.0% likely to have a medium risk anomaly

Notes: The analyzed code is a Babel AST helper (ImportBuilder) used to construct import statements and interop-wrapped imports. It contains no indicators of malicious behavior, data exfiltration, backdoors, or runtime abuses. It operates within a compiler/transpiler context to produce code, not to execute arbitrary user data. Therefore, the code itself does not present security risks or malware indicators under normal usage. This is benign library behavior intended for code transformation.

Confidence: 0.78

Severity: 0.55

From: packages/create-release-branch/package.json → npm/@vitejs/plugin-react@4.7.0 → npm/@babel/helper-module-imports@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helper-module-imports@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @babel/helper-module-transforms is 80.0% likely to have a medium risk anomaly

Notes: The code is a legitimate, static-code transformation utility used in Babel to ensure proper behavior of ES module bindings after transforms. There is no evidence of malicious behavior, data leakage, or external communications within this fragment. It operates purely on AST-level transformations consistent with module import/export handling.

Confidence: 0.80

Severity: 0.50

From: packages/create-release-branch/package.json → npm/@vitejs/plugin-react@4.7.0 → npm/@babel/helper-module-transforms@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helper-module-transforms@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @babel/helpers is 75.0% likely to have a medium risk anomaly

Notes: The analyzed fragment is a conventional Babel/TypeScript-style decorators runtime (applyDecs) responsible for applying decorators to class members and managing metadata and initializers. There is no evidence of malware, backdoors, or external data leakage within this module. While complex, the code behaves as a metadata-driven decorator processor and should be considered low risk when used as intended. Downstream risks depend on the decorators provided by consumers, not this utility itself.

Confidence: 0.75

Severity: 0.60

From: packages/create-release-branch/package.json → npm/@vitejs/plugin-react@4.7.0 → npm/@babel/helpers@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helpers@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @babel/helpers is 61.0% likely to have a medium risk anomaly

Notes: The code fragment is a standard Babel decorator runtime helper (applyDecs2203). Its security posture hinges on the trustworthiness of the supplied decorators. If decorators are from untrusted sources, they can execute arbitrary code during decoration or initialization. The library itself does not exhibit malicious behavior, but this pattern introduces a high-risk surface via external inputs. Recommended mitigations include validating decorator outputs, enforcing sandboxing or runner boundaries for decorators, and auditing decorator sources in the application.

Confidence: 0.61

Severity: 0.58

From: packages/create-release-branch/package.json → npm/@vitejs/plugin-react@4.7.0 → npm/@babel/helpers@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helpers@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @napi-rs/wasm-runtime is 96.0% likely to have a medium risk anomaly

Notes: The fragment appears to be a worker-style filesystem RPC and serialization utility, not malware. It has moderate security concerns if its message channel is exposed to untrusted senders: arbitrary fs property invocation, prototype restoration from serialized metadata, and dynamic global error-constructor selection are insufficiently constrained. No direct malicious payload, secret harvesting, suspicious network activity, or system command execution is present.

Confidence: 0.96

Severity: 0.55

From: packages/create-release-branch/package.json → npm/@tailwindcss/vite@4.3.3 → npm/knip@6.34.0 → npm/@napi-rs/wasm-runtime@1.2.5

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@napi-rs/wasm-runtime@1.2.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @tybys/wasm-util is 65.0% likely to have a medium risk anomaly

Notes: No direct evidence of intentional malware, obfuscation-based payload hiding, or covert network exfiltration in this fragment. The primary security concerns are design/capability risks typical of WASI runtimes: executing externally provided WASM, high-impact filesystem access via injected fs/preopens, environment-variable exposure to the guest, possible host termination via proc_exit, and non-malicious operational risks (busy-wait timer handling and window.prompt stdin blocking; weak RNG fallback to Math.random). Risk is therefore configuration- and trust-boundary-dependent rather than a confirmed implant.

Confidence: 0.65

Severity: 0.52

From: package.json → npm/@tailwindcss/vite@4.3.3 → npm/knip@6.34.0 → npm/@tybys/wasm-util@0.10.4

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@tybys/wasm-util@0.10.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @vitejs/plugin-react is 68.0% likely to have a medium risk anomaly

Notes: No explicit malicious activity detected in this code fragment. The primary risk is inherent to dynamic plugin loading: if an attacker can influence plugin paths or supply malicious plugins, code execution could occur during build-time transforms. This is a supply chain risk rather than an explicit backdoor or payload. The code otherwise aligns with a typical Vite React plugin workflow (Babel options management, conditional React Fast Refresh, and runtime injection).

Confidence: 0.68

Severity: 0.60

From: packages/create-release-branch/package.json → npm/@vitejs/plugin-react@4.7.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@vitejs/plugin-react@4.7.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @vitejs/plugin-react is 61.0% likely to have a medium risk anomaly

Notes: The analyzed code is a typical Vite React plugin fragment responsible for Babel-based transformation, optional React Fast Refresh integration, and runtime script serving. No explicit exfiltration or backdoors are evident. The main security concern is dynamic plugin loading from configuration, which could execute untrusted code if an attacker controls plugin paths or environment. Uphold strict plugin-path whitelisting, validate plugin interfaces, and restrict runtime script reads to trusted locations to mitigate supply-chain risk.

Confidence: 0.61

Severity: 0.55

From: packages/create-release-branch/package.json → npm/@vitejs/plugin-react@4.7.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@vitejs/plugin-react@4.7.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm extend is 78.0% likely to have a medium risk anomaly

Notes: The analyzed code is a conventional object merge utility with explicit safeguards against prototype pollution and support for deep/shallow merging. It is self-contained, non-networking, and suitable for safe inclusion in many JavaScript projects. No malicious behavior detected under the provided scope. Security risk remains low when used with trusted inputs, but care should be taken when merging untrusted objects into critical targets.

Confidence: 0.78

Severity: 0.50

From: packages/create-release-branch/package.json → npm/react-markdown@9.1.0 → npm/extend@3.0.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/extend@3.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm hast-util-to-jsx-runtime is 70.0% likely to have a medium risk anomaly

Notes: This MDX/JSX runtime fragment relies on a dynamic ESTree evaluator to compute values from MDX attributes, which introduces a primary security risk if the evaluator is untrusted or sandboxed improperly. The code includes standard error handling and CSS/style parsing, with no explicit malware indicators. The overall risk is tied to the evaluator; if trusted and sandboxed, risk is moderate, otherwise it could enable arbitrary code execution or data leakage through untrusted input.

Confidence: 0.70

Severity: 0.60

From: packages/create-release-branch/package.json → npm/react-markdown@9.1.0 → npm/hast-util-to-jsx-runtime@2.3.6

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/hast-util-to-jsx-runtime@2.3.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Environment variable access: npm react reads NODE_ENV

Env Vars: NODE_ENV

Location: Package overview

From: packages/create-release-branch/package.json → npm/react@19.3.0

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/react@19.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm semver is 77.0% likely to have a medium risk anomaly

Notes: No malicious behavior detected. This is a legitimate SemVer utility implementation handling version validation, range filtering, and optional increments. Security risk is low for this code fragment; obfuscated indicators are absent. Overall malice likelihood is negligible.

Confidence: 0.77

Severity: 0.50

From: packages/create-release-branch/package.json → npm/@vitejs/plugin-react@4.7.0 → npm/semver@6.3.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/semver@6.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm tapable is 62.0% likely to have a medium risk anomaly

Notes: No overt malicious behavior (no IO, network, filesystem, credential access, or persistence) is present in this fragment. The main security concern is that it uses runtime code generation (new Function) and emits executable JavaScript assembled from options-driven metadata (args/taps/interceptors). If these configuration fields or any emitted expressions are attacker-influenced, it can enable arbitrary code execution in the host. Even with safe codegen, executing provided taps/interceptors means malicious plugins can run arbitrary code with the caller’s privileges.

Confidence: 0.62

Severity: 0.56

From: package.json → npm/@tailwindcss/vite@4.3.3 → npm/eslint-plugin-n@18.4.0 → npm/tapable@2.3.3

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/tapable@2.3.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Environment variable access: npm react-refresh reads NODE_ENV

Env Vars: NODE_ENV

Location: Package overview

From: packages/create-release-branch/package.json → npm/@vitejs/plugin-react@4.7.0 → npm/react-refresh@0.17.0

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/react-refresh@0.17.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Environment variable access: npm scheduler reads NODE_ENV

Env Vars: NODE_ENV

Location: Package overview

From: packages/create-release-branch/package.json → npm/react-dom@19.3.0 → npm/scheduler@0.28.0

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/scheduler@0.28.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

Ignoring alerts on:

  • npm/react-dom@19.3.0
  • npm/@tailwindcss/oxide@4.3.3
  • npm/@tailwindcss/oxide-wasm32-wasi@4.3.3
  • npm/detect-libc@2.1.2
  • npm/@emnapi/core@1.11.3

View full report

@GuillaumeRx
GuillaumeRx added this pull request to stack #36 October 9, 2026 11:09
@GuillaumeRx
GuillaumeRx marked this pull request as ready for review October 9, 2026 12:33
@GuillaumeRx
GuillaumeRx requested a review from a team as a code owner October 9, 2026 12:33
@GuillaumeRx
GuillaumeRx deployed to default-branch October 9, 2026 12:33 — with GitHub Actions Active
Base automatically changed from gr/crb-fixes to main October 9, 2026 14:50
@GuillaumeRx
GuillaumeRx force-pushed the gr/crb-move branch 2 times, most recently from 3c3a47a to 04fc5d6 Compare October 9, 2026 15:08
@GuillaumeRx GuillaumeRx mentioned this pull request Oct 9, 2026
2 of 4 tasks
@GuillaumeRx
GuillaumeRx force-pushed the gr/crb-move branch 2 times, most recently from 29bf913 to 812a0c2 Compare October 9, 2026 15:26
@GuillaumeRx

Copy link
Copy Markdown
Contributor Author

@SocketSecurity ignore npm/@emnapi/core@1.11.3
Reason: Transitive Tailwind build dependency.

@SocketSecurity ignore npm/@tailwindcss/oxide-wasm32-wasi@4.3.3
Reason: Official Tailwind build dependency.

@SocketSecurity ignore npm/@tailwindcss/oxide@4.3.3
Reason: Shell access is expected for Tailwind's native tooling.

@SocketSecurity ignore npm/detect-libc@2.1.2
Reason: Shell access is used to detect the platform.

@SocketSecurity ignore npm/react-dom@19.3.0
Reason: Official React renderer dependency.

cryptodev-2s
cryptodev-2s previously approved these changes Oct 9, 2026
Comment thread oxlint.config.ts Outdated
Comment thread packages/create-release-branch/src/fs.test.ts
@GuillaumeRx
GuillaumeRx added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 189655d Oct 9, 2026
45 checks passed
@GuillaumeRx
GuillaumeRx deleted the gr/crb-move branch October 9, 2026 16:39
GuillaumeRx added a commit to MetaMask/create-release-branch that referenced this pull request Oct 9, 2026
## Explanation

This repository is now archived. The package lives in the
[`release-tools`](https://github.com/MetaMask/release-tools) monorepo,
and all future development and releases happen there.

This replaces the in-progress migration notice with the final archived
notice, as described in step D-3 of the package migration process guide.

## References

- Migration PR: MetaMask/release-tools#35
- Guide:
https://github.com/MetaMask/core/blob/main/docs/processes/package-migration-process-guide.md#phase-d-clean-up-and-release
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants