New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details →
Socket
Book a DemoSign in
Socket

cpro

Package Overview
Dependencies
Maintainers
1
Versions
15
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

cpro - npm Package Compare versions

Comparing version
1.1.8
to
1.1.10
+6
-4
package.json
{
"name": "cpro",
"version": "1.1.8",
"version": "1.1.10",
"description": "Coinbase Pro Fix Client",

@@ -36,10 +36,12 @@ "main": "index.js",

"@types/uuid": "^3.4.4",
"ansi-regex": ">=5.0.1",
"dotenv": "^6.2.0",
"glob-parent": ">=5.1.2",
"gulp": "^4.0.2",
"gulp-env": "^0.4.0",
"gulp-istanbul": "^1.1.3",
"gulp-mocha": "^8.0.0",
"gulp-mocha": "^7.0.2",
"gulp-typescript": "^6.0.0-alpha.1",
"nanoid": ">=3.1.31",
"lodash.template": ">=4.5.0",
"typescript": "^3.2.2"
}
}
+0
-4

@@ -6,6 +6,2 @@ cpro

I got a little inspiration originally from this repo: https://github.com/Saurox/GDAX-Fix-Client
To all the haters out there, I do not think that my code is a copy. His script exposed a lot of the functionality that the api provided. I do not think that also exposing the events that he logs makes it so that I am copying him. I don't think that what I made is trying to be the same as what he made. The api has a way to connect to it. Its not like I can invent how the api works. I think I have had this conversation before. "His method requests the same url" or some nonsense like that. "His method uses the same parameters". Paraphrasing a hypothetical argument with a hypothetical person, not quoting Sirio. I'm sure that Sirio is a nice chap. I've never actually communicated with Sirio. It is interesting that he works for the company that audited the company that I last worked at. Maybe his employer are the people that are being awful.
Methods and parameters found here:

@@ -12,0 +8,0 @@ https://docs.cloud.coinbase.com/exchange/docs/messages