Skip to content

chore(deps): update JavaScript examples to Arcjet 1.12.0 - #213

Merged
davidmytton merged 1 commit into
mainfrom
dev/examples-js-1.12.0
Sep 8, 2026
Merged

chore(deps): update JavaScript examples to Arcjet 1.12.0#213
davidmytton merged 1 commit into
mainfrom
dev/examples-js-1.12.0

Conversation

@qw-in

@qw-in qw-in commented Sep 8, 2026

Copy link
Copy Markdown
Member

We recently released version 1.12.0 of our JavaScript SDK. This gets us up to date

@arcjet-review arcjet-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Arcjet Review — 🔴 High Risk

Decision: Cannot Assess

Rationale: Review failed due to an internal error: unknown error. Escalating to human reviewers.

Review: 5a6c0a30 | Powered by Arcjet Review

@arcjet-review arcjet-review Bot added the needs review Awaiting human review label Sep 8, 2026
@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Publisher changed: npm @arcjet/analyze is now published by quinn-arcjet

Author: quinn-arcjet

From: examples/tanstack-start/package-lock.jsonnpm/@arcjet/astro@1.12.0npm/@arcjet/fastify@1.12.0npm/@arcjet/guard@1.12.0npm/@arcjet/nest@1.12.0npm/@arcjet/next@1.12.0npm/@arcjet/node@1.12.0npm/@arcjet/nuxt@1.12.0npm/@arcjet/react-router@1.12.0npm/@arcjet/sveltekit@1.12.0npm/@arcjet/sensitive-info-rampart@1.12.0npm/@arcjet/analyze@1.12.0

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@arcjet/analyze@1.12.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @arcjet/sensitive-info-rampart under CC-BY-4.0

License: CC-BY-4.0 - The applicable license policy does not permit this license (5) (package/models/rampart/LICENSE)

From: examples/nextjs-sensitive-info/package-lock.jsonnpm/@arcjet/sensitive-info-rampart@1.12.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@arcjet/sensitive-info-rampart@1.12.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Publisher changed: npm arcjet is now published by quinn-arcjet

Author: quinn-arcjet

From: examples/tanstack-start/package-lock.jsonnpm/@arcjet/astro@1.12.0npm/@arcjet/bun@1.12.0npm/@arcjet/fastify@1.12.0npm/@arcjet/nest@1.12.0npm/@arcjet/next@1.12.0npm/@arcjet/node@1.12.0npm/@arcjet/nuxt@1.12.0npm/@arcjet/react-router@1.12.0npm/@arcjet/sveltekit@1.12.0npm/@arcjet/sensitive-info-rampart@1.12.0npm/arcjet@1.12.0

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/arcjet@1.12.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Low adoption: npm @arcjet/nest

Location: Package overview

From: examples/nestjs/package-lock.jsonnpm/@arcjet/nest@1.12.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@arcjet/nest@1.12.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Publisher changed: npm @arcjet/analyze is now published by quinn-arcjet instead of GitHub Actions

New Author: quinn-arcjet

Previous Author: [GitHub Actions](https://socket.dev/npm/user/GitHub Actions)

From: examples/tanstack-start/package-lock.jsonnpm/@arcjet/astro@1.12.0npm/@arcjet/fastify@1.12.0npm/@arcjet/guard@1.12.0npm/@arcjet/nest@1.12.0npm/@arcjet/next@1.12.0npm/@arcjet/node@1.12.0npm/@arcjet/nuxt@1.12.0npm/@arcjet/react-router@1.12.0npm/@arcjet/sveltekit@1.12.0npm/@arcjet/sensitive-info-rampart@1.12.0npm/@arcjet/analyze@1.12.0

ℹ Read more on: This package | This alert | What is new author?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Scrutinize new collaborator additions to packages because they now have the ability to publish code into your dependency tree. Packages should avoid frequent or unnecessary additions or changes to publishing rights.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@arcjet/analyze@1.12.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Publisher changed: npm arcjet is now published by quinn-arcjet instead of GitHub Actions

New Author: quinn-arcjet

Previous Author: [GitHub Actions](https://socket.dev/npm/user/GitHub Actions)

From: examples/tanstack-start/package-lock.jsonnpm/@arcjet/astro@1.12.0npm/@arcjet/bun@1.12.0npm/@arcjet/fastify@1.12.0npm/@arcjet/nest@1.12.0npm/@arcjet/next@1.12.0npm/@arcjet/node@1.12.0npm/@arcjet/nuxt@1.12.0npm/@arcjet/react-router@1.12.0npm/@arcjet/sveltekit@1.12.0npm/@arcjet/sensitive-info-rampart@1.12.0npm/arcjet@1.12.0

ℹ Read more on: This package | This alert | What is new author?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Scrutinize new collaborator additions to packages because they now have the ability to publish code into your dependency tree. Packages should avoid frequent or unnecessary additions or changes to publishing rights.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/arcjet@1.12.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@arcjet-review arcjet-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Arcjet Review — 🔴 High Risk

Decision: Cannot Assess

Rationale: Review failed due to an internal error: unknown error. Escalating to human reviewers.

Review: ea2325d9 | Powered by Arcjet Review

@davidmytton
davidmytton merged commit 4353b96 into main Sep 8, 2026
23 checks passed
@arcjet-review arcjet-review Bot removed the needs review Awaiting human review label Sep 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants