Comparing version 0.1.1 to 0.1.2
{ | ||
"name": "boggle", | ||
"version": "0.1.1", | ||
"version": "0.1.2", | ||
"description": "Boggle grid solver", | ||
@@ -35,4 +35,4 @@ "main": "index.js", | ||
"matrix-paths": "0.0.3", | ||
"prefix-dictionary": "Zolmeister/prefix-dictionary", | ||
"lodash": "~2.4.1" | ||
"lodash": "~2.4.1", | ||
"prefix-dictionary": "0.0.2" | ||
}, | ||
@@ -39,0 +39,0 @@ "devDependencies": { |
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
GitHub dependency
Supply chain riskContains a dependency which resolves to a GitHub URL. Dependencies fetched from GitHub specifiers are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
0
12079
1
+ Addedprefix-dictionary@0.0.2(transitive)
+ Addedtrie@0.2.1(transitive)
Updatedprefix-dictionary@0.0.2