can-view-live
Advanced tools
Comparing version
{ | ||
"name": "can-view-live", | ||
"version": "5.0.0-pre.1", | ||
"version": "5.0.0-pre.2", | ||
"description": "", | ||
@@ -50,3 +50,3 @@ "homepage": "https://canjs.com/doc/can-view-live.html", | ||
"dependencies": { | ||
"can-attribute-observable": "canjs/can-attribute-observable#major", | ||
"can-attribute-observable": "^2.0.0-pre.0", | ||
"can-child-nodes": "^1.0.0", | ||
@@ -62,5 +62,5 @@ "can-diff": "^1.5.0", | ||
"can-symbol": "^1.4.1", | ||
"can-view-callbacks": "canjs/can-view-callbacks#major", | ||
"can-view-callbacks": "^5.0.0-pre.1", | ||
"can-view-parser": "^4.0.0", | ||
"can-view-target": "canjs/can-view-target#major" | ||
"can-view-target": "^5.0.0-pre.0" | ||
}, | ||
@@ -67,0 +67,0 @@ "devDependencies": { |
GitHub dependency
Supply chain riskContains a dependency which resolves to a GitHub URL. Dependencies fetched from GitHub specifiers are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 3 instances in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 3 instances in 1 package
0
-100%0
-100%86719
-0.07%+ Added
+ Added
+ Added
+ Added
+ Added
Updated