Skip to content

update tools - #31

Merged
shocknet-justin merged 5 commits into
stagingfrom
tools-update
Sep 28, 2026
Merged

shocknet-justin merged 5 commits into
stagingfrom
tools-update

Conversation

@boufni95

Copy link
Copy Markdown
Collaborator

No description provided.

@socket-security

socket-security Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​scure/​base@​1.1.1 ⏵ 2.4.010010010087 +6100
Updatednostr-tools@​2.15.1 ⏵ 2.25.29910010094 +2100

View full report

@shocknet-justin
shocknet-justin changed the base branch from main to staging September 26, 2026 02:55
shocknet-justin

This comment was marked as outdated.

@shocknet-justin
shocknet-justin dismissed their stale review September 26, 2026 03:03

Approved by mistake; review still in progress.

shocknet-justin and others added 2 commits September 26, 2026 11:00
…1.8.0

- Restore typescript/rimraf to devDependencies and regenerate the lockfile
  from staging, which drops the downgraded, vulnerable glob/minimatch.
- Drop the @scure/base override; it only affected local installs.
- Use pool.subscribe (single filter), which has the same signature in
  nostr-tools 2.15 and 2.25, so caller-supplied older pools keep working.
- Make all AbstractSimplePool imports type-only and point nenroll at the
  same abstract-pool path as the rest.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@shocknet-justin
shocknet-justin merged commit e91f02c into staging Sep 28, 2026
5 checks passed
@shocknet-justin
shocknet-justin deleted the tools-update branch September 28, 2026 15:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants