Skip to content

Conversation

@github-actions
Copy link
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@keystar/[email protected]

Patch Changes

@keystatic/[email protected]

Patch Changes

@keystatic/[email protected]

Patch Changes

@keystatic/[email protected]

Patch Changes

@keystatic/[email protected]

Patch Changes

@keystar/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@example/[email protected]

Patch Changes

@keystatic/[email protected]

Patch Changes

[email protected]

Patch Changes

@socket-security
Copy link

socket-security bot commented Aug 26, 2025

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: npm @fontsource/inter under OFL-1.1

License: OFL-1.1 - the applicable license policy does not allow this license (4) (npm metadata)

License: OFL-1.1 - the applicable license policy does not allow this license (4) (package/LICENSE)

License: OFL-1.1 - the applicable license policy does not allow this license (4) (package/package.json)

From: docs/package.jsonnpm/@fontsource/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@fontsource/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions github-actions bot force-pushed the changeset-release/main branch 3 times, most recently from 8f217cd to cfe7e2e Compare December 14, 2025 23:14
@github-actions github-actions bot force-pushed the changeset-release/main branch from cfe7e2e to b47e2a6 Compare December 15, 2025 23:40
@socket-security
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant