@yarnpkg/pnpify
Advanced tools
Comparing version 2.0.0-rc.9 to 2.0.0-rc.11
{ | ||
"name": "@yarnpkg/pnpify", | ||
"version": "2.0.0-rc.9", | ||
"version": "2.0.0-rc.11", | ||
"main": "./lib/index.js", | ||
@@ -8,3 +8,3 @@ "bin": "./lib/cli.js", | ||
"dependencies": { | ||
"@yarnpkg/fslib": "2.0.0-rc.8", | ||
"@yarnpkg/fslib": "2.0.0-rc.11", | ||
"comment-json": "^2.2.0", | ||
@@ -15,3 +15,3 @@ "cross-spawn": "^6.0.5" | ||
"@yarnpkg/monorepo": "0.0.0", | ||
"@yarnpkg/pnp": "2.0.0-rc.8", | ||
"@yarnpkg/pnp": "2.0.0-rc.11", | ||
"eslint": "^5.16.0", | ||
@@ -34,3 +34,3 @@ "typescript": "next" | ||
"postpack": "rm -rf lib", | ||
"prepack": "run build:compile packages/yarnpkg-pnpify", | ||
"prepack": "run build:compile \"$(pwd)\"", | ||
"release": "yarn npm publish", | ||
@@ -37,0 +37,0 @@ "test": "run test:unit packages/yarnpkg-pnpify" |
Dynamic require
Supply chain riskDynamic require can indicate the package is performing dangerous or unsafe dynamic code execution.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 1 instance in 1 package
39430
19
908
14
+ Added@yarnpkg/fslib@2.0.0-rc.11(transitive)
+ Added@yarnpkg/libzip@2.0.0-rc.5(transitive)
+ Addedfs.realpath@1.0.0(transitive)
+ Addedglob@7.2.3(transitive)
+ Addedinflight@1.0.6(transitive)
+ Addedinherits@2.0.4(transitive)
+ Addedonce@1.4.0(transitive)
+ Addedpath-is-absolute@1.0.1(transitive)
+ Addedrimraf@2.7.1(transitive)
+ Addedtmp@0.1.0(transitive)
+ Addedwrappy@1.0.2(transitive)
- Removed@yarnpkg/fslib@2.0.0-rc.8(transitive)
- Removed@yarnpkg/libzip@2.0.0-rc.3(transitive)
- Removedos-tmpdir@1.0.2(transitive)
- Removedtmp@0.0.33(transitive)
Updated@yarnpkg/fslib@2.0.0-rc.11