@architect/inventory
Advanced tools
+2
-2
| { | ||
| "name": "@architect/inventory", | ||
| "version": "6.0.0-RC.0", | ||
| "version": "6.0.0", | ||
| "description": "Architect project resource enumeration utility", | ||
@@ -26,3 +26,3 @@ "main": "src/index.js", | ||
| "@architect/parser": "~8.0.1", | ||
| "@architect/utils": "~6.0.0-RC.1", | ||
| "@architect/utils": "~6.0.0", | ||
| "@aws-lite/client": "^0.23.2", | ||
@@ -29,0 +29,0 @@ "@aws-lite/ssm": "^0.2.5" |
Dynamic require
Supply chain riskDynamic require can indicate the package is performing dangerous or unsafe dynamic code execution.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 2 instances in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
Long strings
Supply chain riskContains long string literals, which may be a sign of obfuscated or packed code.
Found 1 instance in 1 package
Dynamic require
Supply chain riskDynamic require can indicate the package is performing dangerous or unsafe dynamic code execution.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 2 instances in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
Long strings
Supply chain riskContains long string literals, which may be a sign of obfuscated or packed code.
Found 1 instance in 1 package
No v1
QualityPackage is not semver >=1. This means it is not stable and does not support ^ ranges.
Found 1 instance in 1 package
1
-50%138072
-0.01%Updated