@cloudbase/framework-plugin-container
Advanced tools
+3
-3
| { | ||
| "name": "@cloudbase/framework-plugin-container", | ||
| "version": "1.3.1-beta.17+0462cb6", | ||
| "version": "1.3.1", | ||
| "description": "云开发 Tencent CloudBase Framework Container Plugin 插件,将项目下的后端应用一键部署云开发云托管环境,提供自动弹性伸缩的高性能容器服务。", | ||
@@ -33,3 +33,3 @@ "author": "Tencent CloudBase Team", | ||
| "dependencies": { | ||
| "@cloudbase/framework-core": "^1.3.1-beta.17+0462cb6", | ||
| "@cloudbase/framework-core": "^1.3.1", | ||
| "archiver": "^4.0.1", | ||
@@ -45,3 +45,3 @@ "fs-extra": "^8.1.0" | ||
| }, | ||
| "gitHead": "0462cb6b8f1594935813e9c2bb5e21e8dfdee28c" | ||
| "gitHead": "bdc0c22449c0792a09b104a5b00f7f9b685e3e37" | ||
| } |
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 1 instance in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 2 instances in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 1 instance in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 2 instances in 1 package
No v1
QualityPackage is not semver >=1. This means it is not stable and does not support ^ ranges.
Found 1 instance in 1 package
0
-100%0
-100%61598
-0.05%