alea-random
Advanced tools
Comparing version 1.1.0 to 1.1.1
{ | ||
"name": "alea-random", | ||
"version": "1.1.0", | ||
"version": "1.1.1", | ||
"description": "`lodash.random` but using Alea", | ||
@@ -29,3 +29,3 @@ "keywords": [ | ||
"lodash.isstring": "^2.4.1", | ||
"node-uuid": "^1.4.1" | ||
"node-uuid": "KenanY/node-uuid" | ||
}, | ||
@@ -32,0 +32,0 @@ "devDependencies": { |
GitHub dependency
Supply chain riskContains a dependency which resolves to a GitHub URL. Dependencies fetched from GitHub specifiers are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
5290
1
1
- Removednode-uuid@1.4.8(transitive)
Updatednode-uuid@KenanY/node-uuid