Comparing version 0.0.4 to 0.0.5
{ | ||
"name": "awsass", | ||
"description": "AWSASS is an assistant to AWS, mostly for running better scripts.", | ||
"version": "0.0.4", | ||
"version": "0.0.5", | ||
"author": "Jsonize", | ||
@@ -17,3 +17,3 @@ "repository": "https://github.com/jsonize/awsass", | ||
"aws-sdk": "", | ||
"node-getopt": "https://github.com/tuxpoldo/node-getopt" | ||
"node-getopt": "git+https://git@github.com/tuxpoldo/node-getopt" | ||
}, | ||
@@ -20,0 +20,0 @@ "files": [ |
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable and can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
HTTP dependency
Supply chain riskContains a dependency which resolves to a remote HTTP URL which could be used to inject untrusted code and reduce overall package reliability.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
3073