Comparing version 2.1.3 to 2.2.0
{ | ||
"name": "bin-build", | ||
"version": "2.1.3", | ||
"version": "2.2.0", | ||
"description": "Easily build binaries", | ||
@@ -28,3 +28,3 @@ "license": "MIT", | ||
"archive-type": "^3.0.1", | ||
"decompress": "kevva/decompress#d1f881352b48b9f04318a046dc5033e6fae7a233", | ||
"decompress": "^3.0.0", | ||
"download": "^4.1.2", | ||
@@ -31,0 +31,0 @@ "exec-series": "^1.0.0", |
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
GitHub dependency
Supply chain riskContains a dependency which resolves to a GitHub URL. Dependencies fetched from GitHub specifiers are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
0
0
5688
Updateddecompress@^3.0.0