@colony/colony-js-contract-client
Advanced tools
Comparing version 1.14.1-no.poll to 1.14.2
{ | ||
"name": "@colony/colony-js-contract-client", | ||
"version": "1.14.1-no.poll", | ||
"version": "1.14.2", | ||
"description": "Method-like interface for Smart Contracts", | ||
@@ -61,3 +61,3 @@ "keywords": [ | ||
"bs58": "^4.0.1", | ||
"ethers": "JoinColony/ethers.js#v3-no-poll", | ||
"ethers": "^3.0.29", | ||
"lodash.flatmap": "^4.5.0", | ||
@@ -77,3 +77,3 @@ "lodash.isequal": "^4.5.0", | ||
}, | ||
"gitHead": "015dfa5f820531c758b644d4cc5f4336a569d48a" | ||
"gitHead": "08e436d69a68d1727673470bb8367df786ba6343" | ||
} |
GitHub dependency
Supply chain riskContains a dependency which resolves to a GitHub URL. Dependencies fetched from GitHub specifiers are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
No v1
QualityPackage is not semver >=1. This means it is not stable and does not support ^ ranges.
Found 1 instance in 1 package
0
0
0
1325420
+ Addedaes-js@3.0.0(transitive)
+ Addedbrorand@1.1.0(transitive)
+ Addedelliptic@6.3.3(transitive)
+ Addedethers@3.0.29(transitive)
+ Addedhash.js@1.1.7(transitive)
+ Addedinherits@2.0.1(transitive)
+ Addedjs-sha3@0.5.7(transitive)
+ Addedminimalistic-assert@1.0.1(transitive)
+ Addedscrypt-js@2.0.3(transitive)
+ Addedsetimmediate@1.0.4(transitive)
+ Addeduuid@2.0.1(transitive)
+ Addedxmlhttprequest@1.8.0(transitive)
Updatedethers@^3.0.29