Comparing version 0.1.2 to 0.1.3-beta
{ | ||
"name": "bakeryjs", | ||
"version": "0.1.2", | ||
"version": "0.1.3-beta", | ||
"description": "FBP-inspired library", | ||
@@ -28,4 +28,3 @@ "main": "build/index", | ||
"ajv": "^6.10.2", | ||
"async": "^2.6.2", | ||
"better-queue": "^3.8.10", | ||
"better-queue": "github:Socialbakers/better-queue", | ||
"debug": "^4.1.1", | ||
@@ -32,0 +31,0 @@ "sb-jsnetworkx": "^0.3.6", |
GitHub dependency
Supply chain riskContains a dependency which resolves to a GitHub URL. Dependencies fetched from GitHub specifiers are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
155013
5
0
1
- Removedasync@^2.6.2
- Removedasync@2.6.4(transitive)
- Removedbetter-queue@3.8.12(transitive)
- Removedbetter-queue-memory@1.0.4(transitive)
- Removednode-eta@0.9.0(transitive)
- Removeduuid@9.0.1(transitive)