Comparing version 0.2.2 to 0.2.3
{ | ||
"name": "ddp", | ||
"version": "0.2.2", | ||
"version": "0.2.3", | ||
"description": "Node.js module to connect to servers using DDP protocol.", | ||
@@ -13,3 +13,3 @@ "author": "Tom Coleman <tom@thesnail.org> (http://tom.thesnail.org), Mike Bannister <notimpossiblemike@gmail.com> (http://po.ssibiliti.es)", | ||
"dependencies": { | ||
"ws": "git://github.com/possibilities/ws.git#slim-dependencies", | ||
"ws": ">=0.4.23", | ||
"underscore": ">=1.3.3" | ||
@@ -16,0 +16,0 @@ }, |
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
0
6165
+ Addedws@8.18.0(transitive)
Updatedws@>=0.4.23