can-view-live
Advanced tools
Comparing version
{ | ||
"name": "can-view-live", | ||
"version": "5.0.0-pre.0", | ||
"version": "5.0.0-pre.1", | ||
"description": "", | ||
@@ -55,4 +55,4 @@ "homepage": "https://canjs.com/doc/can-view-live.html", | ||
"can-fragment": "^1.0.0", | ||
"can-observation": "canjs/can-observation#dom-queue", | ||
"can-queues": "canjs/can-queues#dom-queue", | ||
"can-observation": "^4.2.0", | ||
"can-queues": "^1.3.0", | ||
"can-reflect": "^1.10.2", | ||
@@ -59,0 +59,0 @@ "can-reflect-dependencies": "^1.0.1", |
GitHub dependency
Supply chain riskContains a dependency which resolves to a GitHub URL. Dependencies fetched from GitHub specifiers are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 2 instances in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 2 instances in 1 package
3
-40%3
-40%86776
-0.05%Updated
Updated