Skip to content

feat: Add World ID 4.0 support#231

Open
Takaros999 wants to merge 3 commits intomainfrom
takis/world-id-v4-support
Open

feat: Add World ID 4.0 support#231
Takaros999 wants to merge 3 commits intomainfrom
takis/world-id-v4-support

Conversation

@Takaros999
Copy link
Copy Markdown
Contributor

@Takaros999 Takaros999 commented Mar 25, 2026

v4-simulator-demo.mp4

@vercel
Copy link
Copy Markdown

vercel bot commented Mar 25, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
worldcoin-simulator Ready Ready Preview, Comment Mar 26, 2026 4:14pm

Request Review

@Takaros999 Takaros999 changed the title feat: Add World ID 4.0 sidecar feat: Add World ID 4.0 support Mar 25, 2026
@socket-security
Copy link
Copy Markdown

socket-security bot commented Mar 25, 2026

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: cargo aws-lc-sys is 85.0% likely obfuscated

Confidence: 0.85

Location: Package overview

From: ?cargo/rustls@0.23.37cargo/aws-lc-sys@0.39.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/aws-lc-sys@0.39.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: cargo aws-lc-sys is 72.0% likely obfuscated

Confidence: 0.72

Location: Package overview

From: ?cargo/rustls@0.23.37cargo/aws-lc-sys@0.39.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/aws-lc-sys@0.39.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_collections under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_collections-2.1.1/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_collections-2.1.1/LICENSE)

From: ?cargo/icu_collections@2.1.1

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_collections@2.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_locale_core under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_locale_core-2.1.1/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_locale_core-2.1.1/LICENSE)

From: ?cargo/icu_locale_core@2.1.1

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_locale_core@2.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_normalizer_data under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_normalizer_data-2.1.1/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_normalizer_data-2.1.1/LICENSE)

From: ?cargo/icu_normalizer_data@2.1.1

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_normalizer_data@2.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_normalizer under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_normalizer-2.1.1/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_normalizer-2.1.1/LICENSE)

From: ?cargo/icu_normalizer@2.1.1

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_normalizer@2.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_properties_data under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_properties_data-2.1.2/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_properties_data-2.1.2/LICENSE)

From: ?cargo/icu_properties_data@2.1.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_properties_data@2.1.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_properties under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_properties-2.1.2/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_properties-2.1.2/LICENSE)

From: ?cargo/icu_properties@2.1.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_properties@2.1.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo icu_provider under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_provider-2.1.1/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (icu_provider-2.1.1/LICENSE)

From: ?cargo/icu_provider@2.1.1

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/icu_provider@2.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo litemap under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (litemap-0.8.1/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (litemap-0.8.1/LICENSE)

From: ?cargo/litemap@0.8.1

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/litemap@0.8.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo potential_utf under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (potential_utf-0.1.4/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (potential_utf-0.1.4/LICENSE)

From: ?cargo/potential_utf@0.1.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/potential_utf@0.1.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo sha3-asm under GPL-1.0+

License: GPL-1.0+ - the applicable license policy does not allow this license (4) (sha3-asm-0.1.5/cryptogams/arm/poly1305-armv4.pl)

License: GPL-1.0+ - the applicable license policy does not allow this license (4) (sha3-asm-0.1.5/cryptogams/mips/poly1305-mips.pl)

License: GPL-1.0+ - the applicable license policy does not allow this license (4) (sha3-asm-0.1.5/cryptogams/arm/poly1305-armv8.pl)

License: GPL-1.0+ - the applicable license policy does not allow this license (4) (sha3-asm-0.1.5/cryptogams/arm/sha512-armv8.pl)

License: GPL-1.0+ - the applicable license policy does not allow this license (4) (sha3-asm-0.1.5/cryptogams/arm/ghashv8-armx.pl)

From: ?cargo/sha3-asm@0.1.5

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/sha3-asm@0.1.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo tinystr under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (tinystr-0.8.2/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (tinystr-0.8.2/LICENSE)

From: ?cargo/tinystr@0.8.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/tinystr@0.8.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo unicode-ident under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (unicode-ident-1.0.24/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (unicode-ident-1.0.24/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (unicode-ident-1.0.24/LICENSE-UNICODE)

From: ?cargo/tower-http@0.6.8cargo/tracing@0.1.44cargo/axum@0.8.8cargo/serde_json@1.0.149cargo/rustls@0.23.37cargo/tokio@1.50.0cargo/rand@0.8.5cargo/serde@1.0.228cargo/unicode-ident@1.0.24

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/unicode-ident@1.0.24. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo webpki-roots under CDLA-Permissive-2.0

License: CDLA-Permissive-2.0 - the applicable license policy does not allow this license (4) (webpki-roots-0.26.11/Cargo.toml)

License: CDLA-Permissive-2.0 - the applicable license policy does not allow this license (4) (webpki-roots-0.26.11/LICENSE)

From: ?cargo/webpki-roots@0.26.11

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/webpki-roots@0.26.11. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo webpki-roots under CDLA-Permissive-2.0

License: CDLA-Permissive-2.0 - the applicable license policy does not allow this license (4) (webpki-roots-1.0.6/Cargo.toml)

License: CDLA-Permissive-2.0 - the applicable license policy does not allow this license (4) (webpki-roots-1.0.6/LICENSE)

From: ?cargo/webpki-roots@1.0.6

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/webpki-roots@1.0.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo writeable under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (writeable-0.6.2/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (writeable-0.6.2/LICENSE)

From: ?cargo/writeable@0.6.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/writeable@0.6.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo yoke-derive under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (yoke-derive-0.8.1/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (yoke-derive-0.8.1/LICENSE)

From: ?cargo/yoke-derive@0.8.1

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/yoke-derive@0.8.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo yoke under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (yoke-0.8.1/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (yoke-0.8.1/LICENSE)

From: ?cargo/yoke@0.8.1

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/yoke@0.8.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zerofrom-derive under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (zerofrom-derive-0.1.6/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (zerofrom-derive-0.1.6/LICENSE)

From: ?cargo/zerofrom-derive@0.1.6

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zerofrom-derive@0.1.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zerofrom under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (zerofrom-0.1.6/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (zerofrom-0.1.6/LICENSE)

From: ?cargo/zerofrom@0.1.6

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zerofrom@0.1.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zerotrie under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (zerotrie-0.2.3/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (zerotrie-0.2.3/LICENSE)

From: ?cargo/zerotrie@0.2.3

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zerotrie@0.2.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zerovec-derive under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (zerovec-derive-0.11.2/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (zerovec-derive-0.11.2/LICENSE)

From: ?cargo/zerovec-derive@0.11.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zerovec-derive@0.11.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zerovec under Unicode-3.0

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (zerovec-0.11.5/Cargo.toml)

License: Unicode-3.0 - the applicable license policy does not allow this license (4) (zerovec-0.11.5/LICENSE)

From: ?cargo/zerovec@0.11.5

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zerovec@0.11.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: cargo zstd-sys under GPL-2.0+

License: GPL-2.0+ - the applicable license policy does not allow this license (4) (zstd-sys-2.0.16+zstd.1.5.7/zstd/COPYING)

From: ?cargo/zstd-sys@2.0.16%2Bzstd.1.5.7

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zstd-sys@2.0.16%2Bzstd.1.5.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@Takaros999 Takaros999 marked this pull request as ready for review March 26, 2026 15:57
Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 54cfca5e9d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

try {
const response = await fetch(targetUrl, {
method: req.method,
headers: { "Content-Type": "application/json" },
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Add sidecar authorization header in proxy

The proxy call to the sidecar only sets Content-Type and never sends an Authorization header, but the new sidecar middleware (sidecar/src/auth.rs) rejects every request without Authorization: Bearer <BEARER_TOKEN> and even returns 500 when the token is unset. In practice this makes the v4 flow fail for all /api/sidecar/* calls (401/500 from sidecar) even when the frontend request is otherwise valid.

Useful? React with 👍 / 👎.


setStatus(Status.Pending);

const identityIndex = parseInt(activeIdentity.id, 10);
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Use a real identity index for v4 sidecar requests

Computing identityIndex with parseInt(activeIdentity.id, 10) is incorrect because simulator identity IDs are hex commitment strings (e.g. 0x...), so this expression evaluates to 0 and always targets the first sidecar identity. When multiple identities are configured, selecting any non-first identity will generate/submit a proof for the wrong identity, corrupting verification results.

Useful? React with 👍 / 👎.

* chore: Run linter

* spellcheck

* add bearer token
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants