@wmfs/xml-flatten2csv
Advanced tools
Comparing version 1.7.0 to 1.8.0
@@ -0,1 +1,8 @@ | ||
# [1.8.0](https://github.com/wmfs/xml-flatten2csv/compare/v1.7.0...v1.8.0) (2021-05-11) | ||
### 🛠 Builds | ||
* **deps:** revert jsonpath to 1.1.1 [ch6167] ([461132a](https://github.com/wmfs/xml-flatten2csv/commit/461132a473b092c1acca2049ac503fe6f1aefe3b)) | ||
# [1.7.0](https://github.com/wmfs/xml-flatten2csv/compare/v1.6.0...v1.7.0) (2021-05-10) | ||
@@ -2,0 +9,0 @@ |
{ | ||
"name": "@wmfs/xml-flatten2csv", | ||
"version": "1.7.0", | ||
"version": "1.8.0", | ||
"description": "Flattened XML file to CSV file", | ||
@@ -24,3 +24,3 @@ "author": "West Midlands Fire Service", | ||
"dependencies": { | ||
"jsonpath": "wmfs/jsonpath#master", | ||
"jsonpath": "1.1.1", | ||
"mkdirp": "1.0.4", | ||
@@ -27,0 +27,0 @@ "sax": "1.2.4" |
GitHub dependency
Supply chain riskContains a dependency which resolves to a GitHub URL. Dependencies fetched from GitHub specifiers are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
87544
0
0
+ Addeddeep-is@0.1.4(transitive)
+ Addedescodegen@1.14.3(transitive)
+ Addedesprima@1.2.24.0.1(transitive)
+ Addedestraverse@4.3.0(transitive)
+ Addedesutils@2.0.3(transitive)
+ Addedfast-levenshtein@2.0.6(transitive)
+ Addedjsonpath@1.1.1(transitive)
+ Addedlevn@0.3.0(transitive)
+ Addedoptionator@0.8.3(transitive)
+ Addedprelude-ls@1.1.2(transitive)
+ Addedsource-map@0.6.1(transitive)
+ Addedstatic-eval@2.0.2(transitive)
+ Addedtype-check@0.3.2(transitive)
+ Addedunderscore@1.12.1(transitive)
+ Addedword-wrap@1.2.5(transitive)
Updatedjsonpath@1.1.1