@moneybutton/json-api
Advanced tools
+2
-2
| { | ||
| "name": "@moneybutton/json-api", | ||
| "version": "0.38.7", | ||
| "version": "0.38.8", | ||
| "description": "Money Button isomorphic JSON API utilities.", | ||
@@ -67,3 +67,3 @@ "main": "dist/moneybutton.json-api.cjs.js", | ||
| }, | ||
| "gitHead": "20cbc19ffeb4c87aebc4d863dae036c44166387e" | ||
| "gitHead": "00adacccdc10abeb9c1196b3d2007c86dfbb2178" | ||
| } |
Uses eval
Supply chain riskPackage uses dynamic code execution (e.g., eval()), which is a dangerous practice. This can prevent the code from running in certain environments and increases the risk that the code may contain exploits or malicious behavior.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
Uses eval
Supply chain riskPackage uses dynamic code execution (e.g., eval()), which is a dangerous practice. This can prevent the code from running in certain environments and increases the risk that the code may contain exploits or malicious behavior.
Found 1 instance in 1 package
1
-50%