@rspack/binding
Advanced tools
+12
-12
| { | ||
| "name": "@rspack/binding", | ||
| "version": "2.0.3", | ||
| "version": "2.0.4", | ||
| "license": "MIT", | ||
@@ -26,3 +26,3 @@ "description": "Node binding for rspack", | ||
| "@napi-rs/wasm-runtime": "1.1.4", | ||
| "@types/node": "^20.19.40", | ||
| "@types/node": "^20.19.41", | ||
| "emnapi": "1.10.0", | ||
@@ -58,12 +58,12 @@ "typescript": "^6.0.3" | ||
| "optionalDependencies": { | ||
| "@rspack/binding-win32-arm64-msvc": "2.0.3", | ||
| "@rspack/binding-darwin-arm64": "2.0.3", | ||
| "@rspack/binding-linux-arm64-gnu": "2.0.3", | ||
| "@rspack/binding-wasm32-wasi": "2.0.3", | ||
| "@rspack/binding-linux-arm64-musl": "2.0.3", | ||
| "@rspack/binding-win32-ia32-msvc": "2.0.3", | ||
| "@rspack/binding-darwin-x64": "2.0.3", | ||
| "@rspack/binding-win32-x64-msvc": "2.0.3", | ||
| "@rspack/binding-linux-x64-musl": "2.0.3", | ||
| "@rspack/binding-linux-x64-gnu": "2.0.3" | ||
| "@rspack/binding-win32-arm64-msvc": "2.0.4", | ||
| "@rspack/binding-darwin-arm64": "2.0.4", | ||
| "@rspack/binding-linux-arm64-gnu": "2.0.4", | ||
| "@rspack/binding-linux-arm64-musl": "2.0.4", | ||
| "@rspack/binding-win32-ia32-msvc": "2.0.4", | ||
| "@rspack/binding-wasm32-wasi": "2.0.4", | ||
| "@rspack/binding-win32-x64-msvc": "2.0.4", | ||
| "@rspack/binding-linux-x64-gnu": "2.0.4", | ||
| "@rspack/binding-linux-x64-musl": "2.0.4", | ||
| "@rspack/binding-darwin-x64": "2.0.4" | ||
| }, | ||
@@ -70,0 +70,0 @@ "scripts": { |
Sorry, the diff of this file is too big to display
Potential vulnerability
Supply chain riskInitial human review suggests the presence of a vulnerability in this package. It is pending further analysis and confirmation.
Found 1 instance in 1 package
Shell access
Supply chain riskThis module accesses the system shell. Accessing the system shell increases the risk of executing arbitrary code.
Found 1 instance in 1 package
Dynamic require
Supply chain riskDynamic require can indicate the package is performing dangerous or unsafe dynamic code execution.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 2 instances in 1 package
Long strings
Supply chain riskContains long string literals, which may be a sign of obfuscated or packed code.
Found 1 instance in 1 package
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
Found 1 instance in 1 package
Potential vulnerability
Supply chain riskInitial human review suggests the presence of a vulnerability in this package. It is pending further analysis and confirmation.
Found 1 instance in 1 package
Shell access
Supply chain riskThis module accesses the system shell. Accessing the system shell increases the risk of executing arbitrary code.
Found 1 instance in 1 package
Dynamic require
Supply chain riskDynamic require can indicate the package is performing dangerous or unsafe dynamic code execution.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 2 instances in 1 package
Long strings
Supply chain riskContains long string literals, which may be a sign of obfuscated or packed code.
Found 1 instance in 1 package
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
Found 1 instance in 1 package
117098
-0.1%3375
-0.12%