dev-dependency-management
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
SecuritySecuritydata/sample-dependency-manifest.example.json
MEDIUMSecurityMEDIUM
data/sample-dependency-manifest.example.json
The fragment is non-executable dependency metadata and shows no direct malicious behavior or obfuscation. It does reveal significant supply-chain security exposure from multiple outdated, declared-vulnerable production dependencies, especially serialize-javascript and PyYAML, plus incomplete Node.js SBOM coverage and an unpinned Python package-manager version. Remediation should prioritize the critical and high-severity dependencies and strengthen reproducible-build metadata.
Confidence: 98%Severity: 78%
Audit Metadata