@celo/utils
Advanced tools
Comparing version
{ | ||
"name": "@celo/utils", | ||
"version": "0.0.4", | ||
"version": "0.0.5-dappkit1", | ||
"description": "Celo common utils", | ||
@@ -9,5 +9,5 @@ "author": "Celo", | ||
"types": "./lib/index.d.ts", | ||
"files": ["lib/**/*"], | ||
"scripts": { | ||
"pretest": "tsc", | ||
"postinstall": "yarn run build || exit 1 && yarn run prettify || true", | ||
"prettify": "yarn run prettier --config ../../.prettierrc.js --write '{contracts,types,lib}/**/*.+(ts|tsx|js|jsx)'", | ||
@@ -19,3 +19,3 @@ "build": "tsc", | ||
"dependencies": { | ||
"@umpirsky/country-list": "https://github.com/umpirsky/country-list#05fda51", | ||
"@umpirsky/country-list": "git://github.com/umpirsky/country-list#05fda51", | ||
"bignumber.js": "^7.2.0", | ||
@@ -22,0 +22,0 @@ "bn.js": "4.11.8", |
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable and can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
Major refactor
Supply chain riskPackage has recently undergone a major refactor. It may be unstable or indicate significant internal changes. Use caution when updating to versions that include significant changes.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
HTTP dependency
Supply chain riskContains a dependency which resolves to a remote HTTP URL which could be used to inject untrusted code and reduce overall package reliability.
Found 1 instance in 1 package
Install scripts
Supply chain riskInstall scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.
Found 1 instance in 1 package
374231
561.41%42
100%2521
68.52%1
-50%2
Infinity%