Skip to content

Bump actions/setup-node from 6.0.0 to 6.1.0#474

Merged
some-natalie merged 1 commit intomainfrom
dependabot/github_actions/actions/setup-node-6.1.0
Dec 3, 2025
Merged

Bump actions/setup-node from 6.0.0 to 6.1.0#474
some-natalie merged 1 commit intomainfrom
dependabot/github_actions/actions/setup-node-6.1.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Dec 3, 2025

Bumps actions/setup-node from 6.0.0 to 6.1.0.

Release notes

Sourced from actions/setup-node's releases.

v6.1.0

What's Changed

Enhancement:

Dependency updates:

Documentation update:

Full Changelog: actions/setup-node@v6...v6.1.0

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.0.0 to 6.1.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@2028fbc...395ad32)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code minor Minor semver labels Dec 3, 2025
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Dec 3, 2025

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/service-client-generator-generic.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/out-file.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./our-options
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/protoc/protoc.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM discover/system/platform get system identification os.platform()
os.arch()
-MEDIUM fs/path/relative references and possibly executes relative path ./util
-MEDIUM net/download download files failed to download protoc v
download the release
await httpDownload
-MEDIUM process/create create child process require('child_process')
-LOW exec/plugin references a 'plugin' let plugin of findProtocPlugins
plugin in node
xxx plugins in
-LOW fs/file/write writes to file writeFileSync
-LOW fs/path/usr_bin path reference within /usr/bin /usr/bin/env
-LOW net/url/embedded contains embedded HTTPS URLs https://github.com/protocolbuffers/protobuf/releases
-LOW os/env/get Retrieve environment variable values env.PROTOC_RELEASES_
env.PATH

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/node_modules/typescript/lib/protocol.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' interface ConfigurePluginResponse
export interface PluginImport
configurePlugin
pluginName
plugins
-LOW fs/file/open opens files openFile
-LOW fs/tempfile creates temporary files tmpfile

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/protobufts-plugin.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./our-options
./out-file
-LOW exec/plugin references a 'plugin' export declare class ProtobuftsPlugin extends
class ProtobuftsPlugin extends PluginBase
plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/message-interface-generator.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/service-server-generator-generic.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./local-type-name
./generator-base

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/comment-generator.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/file/times_set change file timestamps touch members.
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/descriptor-tree.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./descriptor-info
./google

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/message-type-extensions/google-types.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/google/protobuf/descriptor.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/http/post submits content to websites HTTP
POST
-LOW exec/plugin references a 'plugin' deprecated in favor of using plugins
without additional plugins
-LOW net/http Uses the HTTP protocol HTTP

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/bin/protoc-gen-dump [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' failed to run plugin
new DumpPlugin
-LOW fs/path/usr_bin path reference within /usr/bin /usr/bin/env

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/symbol-table.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./descriptor-info
./generated-file

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/commonjs/symbol-table.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./string-format
-MEDIUM sus/exclamation gets very excited return !!

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/node_modules/typescript/lib/typescriptServices.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM anti-static/obfuscation/js Multiple suspicious string patterns with charAt operations var shouldEnterSuppressNewDiagnosticsContextContext = (
var thisNodeOrAnySubNodesHasError = (
var mayEmitInterveningComments = (
var requireOptionalProperties = (
var __classPrivateFieldGet = (
var __classPrivateFieldSet = (
var createUIStringComparer = (
var eitherHasEffectiveRest = (
var superCallShouldBeFirst = (
var canUseBreakOrContinue = (
var __makeTemplateObject = (
var hasMoreThanFiveLines = (
var hasPrivateIdentifier = (
var useActualIndentation = (
var allowAsyncIterables = (
var declarationFilePath = (
var hasLexicalArguments = (
var lookInPreviousChild = (
var unwrappedReturnType = (
var __setModuleDefault = (
var checkLetConstNames = (
var exportedMemberName = (
var globalTypingsCache = (
var tagNameDeclaration = (
var typeParameterCount = (
var emittedAsTopLevel = (
var inputListOrBundle = (
var sourceMapDataList = (
var __asyncDelegator = (
var __asyncGenerator = (
var excludedMeanings = (
var hasTrailingComma = (
var moduleSourceFile = (
var textToKeywordObj = (
var tokenIndentation = (
var __createBinding = (
var __importDefault = (
var bindingElements = (
var debugObjectHost = (
var minInsertionPos = (
var moduleSpecifier = (
var numVarsSameName = (
var __spreadArrays = (
var compareStrings = (
var estimatedCount = (
var iterationTypes = (
var symbolMeanings = (
var typeParameters = (
var __asyncValues = (
var augmentedName = (
var commentRanges = (
var containsYield = (
var declaringNode = (
var etwModulePath = (
var isConstructor = (
var modifierFlags = (
var nDeclarations = (
var nextLineStart = (
var paddedHexCode = (
var specifierName = (
var triggerReason = (
var __exportStar = (
var __importStar = (
var adjustedNode = (
var exportSymbol = (
var propertyName = (
var segmentValue = (
var shouldBundle = (
var __generator = (
var declBlocked = (
var gutterWidth = (
var indentation = (
var isGenerator = (
var localSymbol = (
var objectFlags = (
var reportError = (
var __decorate = (
var __metadata = (
var assumeTrue = (
var bitsNeeded = (
var completion = (
var exportStar = (
var expression = (
var hasBinding = (
var isOptional = (
var makeStatic = (
var parameters = (
var returnType = (
var substitute = (
var __awaiter = (
var __extends = (
var additions = (
var container = (
var errorNode = (
var __assign = (
var __spread = (
var __values = (
var hasBrace = (
var iterator = (
var noIndent = (
var rootPath = (
var variance = (
var __await = (
var __param = (
var isAsync = (
var literal = (
var meaning = (
var missing = (
var newBody = (
var visited = (
var __read = (
var __rest = (
var create = (
var newRef = (
var params = (
var parent = (
var prefix = (
var result = (
var symbol = (
var array = (
var flags = (
var start = (
var value = (
var curr = (
var flag = (
var info = (
var kind = (
var name = (
var prop = (
var tags = (
var text = (
var end = (
var key = (
var ref = (
var _a = (
var ok = (
var C = (
var i = (
-MEDIUM anti-static/obfuscation/math suspicious junk math operations with charAt var MAX_SMI_X86 = 1073741823;
var maxLength = 150;
var acc = 5381;
charAt
-MEDIUM c2/addr/ip hardcoded IP address 13.7.4.8
24.3.2.2
-MEDIUM c2/tool_transfer/os references multiple operating systems https://
Windows
http://
windows
darwin
Linux
linux
-MEDIUM data/encoding/utf16 assembles strings from UTF-16 code units String.fromCharCode(84 /* T
String.fromCharCode(97 /* a
String.fromCharCode(base64F
String.fromCharCode(ch).toL
String.fromCharCode(charCod
String.fromCharCode(codePoi
String.fromCharCode(codeUni
String.fromCharCode(cookedC
String.fromCharCode(escaped
String.fromCharCode(firstCh
String.fromCharCode.apply(S
String.fromCharCode(value)
-MEDIUM discover/system/platform get system identification process.platform
os.platform()
-MEDIUM evasion/file/prefix possible hidden file path /node_modules/.staging
-MEDIUM exec/cmd executes a command logStartCommand:
-MEDIUM exec/shell/pipe_sh pipes to shell [
-MEDIUM fs/file/create create a new file CreateFileWatcher
-MEDIUM fs/file/delete delete a file DeleteFileOrDirect
-MEDIUM fs/file/times_set change file timestamps touch the current line at all.
touch timestamps
touch them
touch it.
-MEDIUM fs/path/root path reference within /root /root/components/folder1/
-MEDIUM net/download download files to download d
-MEDIUM net/http/form_upload upload content via HTTP form application/json
post
-MEDIUM net/ip/host_port connects to an arbitrary host:port host doesnt support
host).allowsImport
host, oldImport
host.getImport
host), import
host support
host.report
-MEDIUM sus/exclamation gets very excited ALREADY FORMATTED!!
return !!
-MEDIUM sus/leetspeak References 1337 terminology' 1337
-LOW c2/tool_transfer/arch references a specific architecture https://
http://
x86
-LOW crypto/public_key references a 'public key' PublicKey
-LOW data/compression/zlib uses zlib zlib
-LOW data/encoding/base64 Supports base64 encoded strings base64
-LOW data/encoding/int parses integers parseInt(
-LOW data/encoding/json_decode Decodes JSON messages JSON.parse
-LOW data/encoding/json_encode encodes JSON JSON.stringify
-LOW exec/plugin references a 'plugin' List_of_language_service_plugins_6181
external files are added by plugins
List of language service plugins
-LOW fs/directory/create creates directories CreateDirectory
mkdir
-LOW fs/directory/list Uses NodeJS functions to list a directory .readdirSync(
-LOW fs/file/delete_forcibly Forcibly deletes files rm JSX-specific syntax in a SourceFile.
-LOW fs/file/read reads files ReadFile
-LOW fs/file/rename renames files File.rename
-LOW fs/file/stat access filesystem metadata fs.statSync(path
-LOW fs/file/write writes to file writeFileEnsuringDirectories
writeBundleFileInfo:
writeFileCallback
writeFileWorker
writeFileName:
writeFileSync
writeFile:
WriteFile
-LOW fs/symlink_resolve resolves symbolic links realpath
-LOW net/http Uses the HTTP protocol http
-LOW net/url/embedded contains embedded HTTPS URLs https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_
https://en.wikipedia.org/wiki/List_of_XML_and_HTML_character_entity_refer
https://github.com/microsoft/TypeScript/pull/36248/files/5062623f39120171
https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/
https://mail.mozilla.org/pipermail/es-discuss/2011-August/016188.html
https://github.com/Microsoft/TypeScript/pull/11547/files
microsoft/TypeScript#30180
https://bugs.chromium.org/p/v8/issues/detail?id=9560
microsoft/TypeScript#17494
microsoft/TypeScript#18924
microsoft/TypeScript#19955
microsoft/TypeScript#20559
microsoft/TypeScript#20809
microsoft/TypeScript#21246
microsoft/TypeScript#25652
microsoft/TypeScript#33298
microsoft/TypeScript#36098
microsoft/TypeScript#4643
microsoft/TypeScript#7547
microsoft/TypeScript#20547
microsoft/TypeScript#29539
microsoft/TypeScript#32372
https://mathiasbynens.be/notes/javascript-encoding
microsoft/TypeScript#7591
https://www.ecma-international.org/ecma-262/6.0/
https://www.w3.org/TR/html4/struct/text.html
https://github.com/microsoft/typescript-etw
nodejs/node#4002
nodejs/node#5963
https://docs.npmjs.com/files/package.json
nodejs/node#33716
nodejs/node#2649
https://jsdoc.app/about-namepaths.html
https://nodejs.org/api/inspector.html
https://www.ietf.org/rfc/rfc1738.txt
https://www.w3.org/TR/CSS2/text.html
https://github.com/npm/node-semver
https://tc39.github.io/ecma262/
https://aka.ms/tsconfig.json
https://semver.org/
-LOW os/env/get Retrieve environment variable values env.NODE_INSPECTOR_I
env.TSC_NONPOLLING_W
env.TSC_WATCHDIRECTO
env.TS_ETW_MODULE_PA
env.TSC_WATCHFILE
-LOW os/fd/write writes to a file handle system.write(output)
stdout.write(s)
writer.write(s)

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/message-type-generator.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/descriptor-info.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./descriptor-tree
./type-names
./google
-LOW net/url/embedded contains embedded HTTPS URLs https://developers.google.com/protocol-buffers/docs/proto3

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/file-table.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/es2015/google/protobuf/descriptor.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/http/post submits content to websites HTTP
POST
http
-LOW net/http Uses the HTTP protocol HTTP
-LOW net/url/embedded contains embedded HTTPS URLs https://developers.google.com/protocol-buffers/

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/enum-generator.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/node_modules/typescript/lib/lib.esnext.symbol.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW net/http Uses the HTTP protocol http
-LOW net/url/embedded contains embedded HTTP URLs http://www.apache.org/licenses/LICENSE-2.0

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/commonjs/descriptor-tree.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./descriptor-info
./google

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/service-server-generator-grpc.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/generator-base.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/message-type-extensions/internal-binary-read.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/message-type-extensions/internal-binary-write.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/type-names.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./descriptor-info
./descriptor-tree

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/service-client-generator-base.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/local-type-name.js [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/interpreter.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./our-options
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/es2015/typescript-imports.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./foo

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/comment-generator.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/service-client-generator-base.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./local-type-name
./generator-base

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/es2015/plugin-base.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./google
-LOW exec/plugin references a 'plugin' Base class for a protobuf plugin
method to create a plugin
export class PluginBase
passes it to the plugin
failed to run plugin
PluginMessageError
new MyPlugin
-LOW fs/path/usr_bin path reference within /usr/bin /usr/bin/env
-LOW net/url/embedded contains embedded HTTPS URLs timostamm/protobuf-ts#134

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/field-info-generator.js [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/commonjs/descriptor-registry.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./source-code-info
./descriptor-info
./descriptor-tree
./string-format
./type-names
./google
-LOW exec/plugin references a 'plugin' const plugin_1

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/dump-plugin.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' export declare class DumpPlugin extends
class DumpPlugin extends PluginBase
plugin
-LOW fs/directory/create creates directories mkdir

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/message-type-generator.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./generator-base
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/service-server-generator-generic.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/node_modules/typescript/lib/lib.esnext.bigint.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW net/http Uses the HTTP protocol http
-LOW net/url/embedded contains embedded HTTP URLs http://www.apache.org/licenses/LICENSE-2.0

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/es2015/type-names.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./descriptor-info
./google

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/dump-plugin.js [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' class DumpPlugin extends
PluginBase
plugin
-LOW fs/directory/create creates directories mkdir
-LOW fs/file/write writes to file writeFileSync

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/commonjs/descriptor-info.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./string-format
./google

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/enum-generator.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./generator-base
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/commonjs/typescript-import-manager.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./foo

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/field-info-generator.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/commonjs/source-code-info.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./google
-LOW net/url/embedded contains embedded HTTPS URLs https://github.com/protocolbuffers/protobuf/blob/f1ce8663ac88df54cf212d29

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/node_modules/typescript/lib/lib.esnext.asynciterable.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW net/http Uses the HTTP protocol http
-LOW net/url/embedded contains embedded HTTP URLs http://www.apache.org/licenses/LICENSE-2.0

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/google/protobuf/compiler/plugin.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' once before sending them to the plugin
is written to the plugin
The plugin process

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/message-type-extensions/internal-binary-write.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM anti-static/obfuscation/math complex math with parseInt or fromCharCode conversions (mapEntryValueScalarType)
(writerExpressionOrName)
(UnknownFieldHandler)
[fieldPropertyAccess]
[internalBinaryWrite]
(binaryWriteAndJoin)
(messageDescriptor)
(fieldDescriptor)
(defaultValue)
(descriptor)
(methodName)
(scalarType)
parseInt
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/descriptor-registry.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./source-code-info
./descriptor-info
./descriptor-tree
./string-format
./type-names
./google
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/commonjs/typescript-compile.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM sus/exclamation gets very excited return !!
-LOW fs/file/write writes to file writeFile

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/service-server-generator-grpc.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./local-type-name
./generator-base
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/our-options.js [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' PluginMessageError
pluginCredit
-LOW net/tcp/grpc Uses the gRPC Remote Procedure Call framework gRPC

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/message-type-extensions/well-known-types.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM anti-static/obfuscation/math complex math with parseInt or fromCharCode conversions (camelToSnake)
(numberValue)
(sign + secs)
(typeof json)
(descriptor)
01-01T00
12-31T23
parseInt
0001-01
9999-12
-LOW data/encoding/int parses integers parseInt(
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/string-format.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./source-code-info
./descriptor-info
./descriptor-tree
./type-names
./google

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/bin/protoc-gen-ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' failed to run plugin
new ProtobuftsPlugin
-LOW fs/path/usr_bin path reference within /usr/bin /usr/bin/env

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/source-code-info.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./descriptor-info
./descriptor-tree
./google
-LOW net/url/embedded contains embedded HTTPS URLs https://github.com/protocolbuffers/protobuf/blob/f1ce8663ac88df54cf212d29

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/interpreter.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./our-options
./code-gen
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/service-type-generator.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./generator-base
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/es2015/string-format.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./descriptor-info
./google

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/file-table.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM sus/exclamation gets very excited return !!
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/method-info-generator.js [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/typescript-compile.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./generated-file
-LOW fs/file/write writes to file writeFile

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/typescript-imports.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./descriptor-info
./typescript-file
./symbol-table

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/our-options.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./interpreter
-LOW exec/plugin references a 'plugin' readonly pluginCredit
-LOW net/http Uses the HTTP protocol http
-LOW net/tcp/grpc Uses the gRPC Remote Procedure Call framework gRPC

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/message-type-extensions/internal-binary-read.js [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/node_modules/typescript/lib/typescriptServices.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./blah
-MEDIUM fs/path/root path reference within /root /root/blah/tsconfig.json
-MEDIUM net/ip/host_port connects to an arbitrary host:port host can ask import
-LOW crypto/public_key references a 'public key' PublicKey
-LOW data/encoding/base64 Supports base64 encoded strings base64
-LOW exec/plugin references a 'plugin' export interface PluginImport
-LOW fs/file/delete deletes files deleteFile
-LOW fs/file/delete_forcibly Forcibly deletes files rm just-in
-LOW fs/file/write writes to file writeFileCallback
writeFile:
WriteFile
-LOW fs/symlink_resolve resolves symbolic links realpath
-LOW net/http Uses the HTTP protocol http
-LOW net/url/embedded contains embedded HTTPS URLs https://nodejs.org/api/crypto.html
https://nodejs.org/api/fs.html

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/local-type-name.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/message-type-extensions/google-types.js [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW data/encoding/int parses integers parseInt(
-LOW exec/plugin references a 'plugin' plugin
-LOW net/url/embedded contains embedded HTTPS URLs https://developer.mozilla.org/en-US/docs/Web/CSS/color_value

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/out-file.js [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' pluginCredit

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/message-interface-generator.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./local-type-name
./generator-base
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/generated-file.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' A file generated by a plugin
PluginBase

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/service-client-generator-grpc.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/protobufts-plugin.js [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./interpreter
./our-options
./file-table
./code-gen
./out-file
-LOW exec/plugin references a 'plugin' class ProtobuftsPlugin extends
plugins should
PluginBase
-LOW net/tcp/grpc Uses the gRPC Remote Procedure Call framework gRPC

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/message-type-extensions/well-known-types.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/service-type-generator.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/typescript-import-manager.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./descriptor-info
./typescript-file
./generated-file
./symbol-table

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin/build/code-gen/method-info-generator.d.ts [🔵 LOW]

RISK KEY DESCRIPTION EVIDENCE
-LOW exec/plugin references a 'plugin' plugin

Deleted: /tmp/prior-commit/node_modules/@protobuf-ts/plugin-framework/build/types/plugin-base.d.ts [🟡 MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM fs/path/relative references and possibly executes relative path ./generated-file
./google
-LOW exec/plugin references a 'plugin' export declare abstract class PluginBase
Base class for a protobuf plugin
method to create a plugin
passes it to the plugin
failed to run plugin
new MyPlugin
-LOW fs/path/usr_bin path reference within /usr/bin /usr/bin/env

@some-natalie some-natalie merged commit 1528aa5 into main Dec 3, 2025
6 checks passed
@some-natalie some-natalie deleted the dependabot/github_actions/actions/setup-node-6.1.0 branch December 3, 2025 22:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code minor Minor semver

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant