@sanity/cli
Advanced tools
+6
-6
| { | ||
| "name": "@sanity/cli", | ||
| "version": "5.13.0-next.20+2291952261", | ||
| "version": "5.13.0-next.21+da8354c772", | ||
| "description": "Sanity CLI tool for managing Sanity installations, managing plugins, schemas and datasets", | ||
@@ -116,7 +116,7 @@ "keywords": [ | ||
| "xdg-basedir": "^4.0.0", | ||
| "@repo/eslint-config": "5.13.0-next.20+2291952261", | ||
| "@repo/package.config": "5.13.0-next.20+2291952261", | ||
| "@sanity/types": "5.12.0", | ||
| "@repo/test-config": "5.13.0-next.20+2291952261", | ||
| "@repo/tsconfig": "5.13.0-next.20+2291952261" | ||
| "@repo/tsconfig": "5.13.0-next.21+da8354c772", | ||
| "@repo/test-config": "5.13.0-next.21+da8354c772", | ||
| "@repo/package.config": "5.13.0-next.21+da8354c772", | ||
| "@repo/eslint-config": "5.13.0-next.21+da8354c772", | ||
| "@sanity/types": "5.12.0" | ||
| }, | ||
@@ -123,0 +123,0 @@ "peerDependencies": { |
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
Network access
Supply chain riskThis module accesses the network.
Found 1 instance in 1 package
Dynamic require
Supply chain riskDynamic require can indicate the package is performing dangerous or unsafe dynamic code execution.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 9 instances in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
Long strings
Supply chain riskContains long string literals, which may be a sign of obfuscated or packed code.
Found 1 instance in 1 package
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
Network access
Supply chain riskThis module accesses the network.
Found 1 instance in 1 package
Dynamic require
Supply chain riskDynamic require can indicate the package is performing dangerous or unsafe dynamic code execution.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 9 instances in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
Long strings
Supply chain riskContains long string literals, which may be a sign of obfuscated or packed code.
Found 1 instance in 1 package
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
Found 1 instance in 1 package