Skip to content

feat: migrate pnpm#866

Open
YoannNumericite wants to merge 11 commits intomainfrom
feat/pnpm
Open

feat: migrate pnpm#866
YoannNumericite wants to merge 11 commits intomainfrom
feat/pnpm

Conversation

@YoannNumericite
Copy link
Copy Markdown
Contributor

No description provided.

Copy link
Copy Markdown
Collaborator

@revu-bot revu-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

An error occurred: ## ⚠️ PR Review Skipped

2 validation issues found. Review thresholds can be adjusted in .revu.yml.

See why it was skipped and detailed metrics

Issues Found

1. This PR has 57070 lines of diff, which exceeds the limit of 15000 lines.

Suggestion: Consider splitting this PR into smaller chunks. Large diffs are difficult to review thoroughly and may hide important issues.

2. This PR contains files that exceed the size limit: 'formulaire/package-lock.json' (6162 lines of changes), 'formulaire/yarn.lock' (7805 lines of changes), 'package-lock.json' (17465 lines of changes), 'pnpm-lock.yaml' (13905 lines of changes), 'yarn.lock' (9512 lines of changes), which exceeds the limit of 3000. The limit is 3000 lines per file.

Suggestion: Consider refactoring large changes into smaller, more focused modifications. Large file changes are harder to review and understand.

PR Metrics

  • Total files changed: 21
  • Reviewable files: 21
  • Diff size: 57070 lines
  • Documentation files: 1
  • Largest file change: 17465 lines
  • Addition/Deletion ratio: 0.33

This validation helps ensure the bot focuses on PRs where automated review provides the most value.

Revu logs

Copy link
Copy Markdown
Collaborator

@revu-bot revu-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

An error occurred: ## ⚠️ PR Review Skipped

3 validation issues found. Review thresholds can be adjusted in .revu.yml.

See why it was skipped and detailed metrics

Issues Found

1. This PR changes 26 files, which exceeds the limit of 25 files.

Suggestion: Consider breaking this PR into smaller, more focused changes. Large PRs are harder to review effectively and may contain unrelated changes.

2. This PR has 57168 lines of diff, which exceeds the limit of 15000 lines.

Suggestion: Consider splitting this PR into smaller chunks. Large diffs are difficult to review thoroughly and may hide important issues.

3. This PR contains files that exceed the size limit: 'formulaire/package-lock.json' (6162 lines of changes), 'formulaire/yarn.lock' (7805 lines of changes), 'package-lock.json' (17465 lines of changes), 'pnpm-lock.yaml' (13905 lines of changes), 'yarn.lock' (9512 lines of changes), which exceeds the limit of 3000. The limit is 3000 lines per file.

Suggestion: Consider refactoring large changes into smaller, more focused modifications. Large file changes are harder to review and understand.

PR Metrics

  • Total files changed: 26
  • Reviewable files: 26
  • Diff size: 57168 lines
  • Documentation files: 1
  • Largest file change: 17465 lines
  • Addition/Deletion ratio: 0.33

This validation helps ensure the bot focuses on PRs where automated review provides the most value.

Revu logs

@socket-security
Copy link
Copy Markdown

socket-security bot commented Dec 17, 2025

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: pnpm-lock.yamlnpm/entities@4.5.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@4.5.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: pnpm-lock.yamlnpm/entities@4.5.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@4.5.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: pnpm-lock.yamlnpm/entities@6.0.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@6.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@sonarqubecloud
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants