@clearbit-dcp/clearbit.js-core
Advanced tools
Comparing version 0.0.3 to 0.1.0
{ | ||
"name": "@clearbit-dcp/clearbit.js-core", | ||
"author": "Clearbit <support@clearbit.com>", | ||
"version": "0.0.3", | ||
"version": "0.1.0", | ||
"description": "The hassle-free way to integrate analytics into any web application.", | ||
@@ -47,3 +47,3 @@ "keywords": [ | ||
"component-event": "^0.1.4", | ||
"component-querystring": "^2.0.0", | ||
"component-querystring": "git+https://github.com/clearbit/querystring.git", | ||
"component-type": "^1.2.1", | ||
@@ -50,0 +50,0 @@ "component-url": "^0.2.1", |
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
168838
32
1
1
- Removedcomponent-querystring@2.0.1(transitive)
- Removedcomponent-type@1.1.0(transitive)
Updatedcomponent-querystring@git+https://github.com/clearbit/querystring.git