Skip to content

Conversation

@Wxh16144
Copy link
Member

当前 package-diff 只检查了缺失部分,并没有检查有哪些新增。比如 antd-mobile 5.39.0 出现了意外的产物

image

一方便需要担心敏感信息泄漏,另一方便可能会导致 breakchange?本次 PR 加入了新增和差异检查。

(或许可以再加一个开关控制是否检查新增)

before

image

after

image

@socket-security
Copy link

socket-security bot commented May 22, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm-packlist@​10.0.010010010084100
Added@​npmcli/​arborist@​9.1.19810010094100

View full report

@afc163 afc163 merged commit c2b2f29 into ant-design:master Jun 6, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants