Comparing version 0.3.3 to 0.3.4
@@ -14,6 +14,6 @@ { | ||
}, | ||
"version": "0.3.3", | ||
"version": "0.3.4", | ||
"main": "./index.js", | ||
"dependencies": { | ||
"async-json": "git://github.com/tim-kos/async-json.git#a1baed80dab93c0d7f1fa8ae2620f70ff82a24bb", | ||
"async-json": "git://github.com/ckknight/async-json.git#145bb94b4496e5150c453a9e2e14610f93b0e16f", | ||
"resumer": "0.0.0", | ||
@@ -20,0 +20,0 @@ "event-stream": "3.3.0", |
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable and can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable and can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
665050