esbuild
Advanced tools
Comparing version 0.0.0 to 0.0.4
{ | ||
"name": "esbuild", | ||
"version": "0.0.0", | ||
"description": "", | ||
"author": "Evan Wallace", | ||
"license": "ISC" | ||
} | ||
"version": "0.0.4", | ||
"description": "This is a test. Please ignore.", | ||
"scripts": { | ||
"postinstall": "node install.js" | ||
}, | ||
"bin": "bin/esbuild" | ||
} |
Install scripts
Supply chain riskInstall scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.
Found 1 instance in 1 package
Shell access
Supply chain riskThis module accesses the system shell. Accessing the system shell increases the risk of executing arbitrary code.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 2 instances in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
No contributors or author data
MaintenancePackage does not specify a list of contributors or an author in package.json.
Found 1 instance in 1 package
No License Found
License(Experimental) License information could not be found
Found 1 instance in 1 package
Empty package
Supply chain riskPackage does not contain any code. It may be removed, is name squatting, or the result of a faulty package publish.
Found 1 instance in 1 package
No tests
QualityPackage does not have any tests. This is a strong signal of a poorly maintained or low quality package.
Found 1 instance in 1 package
2375
3
52
2
1
2
1
4