🚀 Big News: Socket Acquires Coana to Bring Reachability Analysis to Every Appsec Team.Learn more

gomplate

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install
g

gomplate

Install gomplate with npm

4.1.0
latest
62

Supply Chain Security

100

Vulnerability

52

Quality

82

Maintenance

100

License

GitHub dependency

Supply chain risk

Contains a dependency which resolves to a GitHub URL. Dependencies fetched from GitHub specifiers are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.

Found 1 instance in 1 package

Install scripts

Supply chain risk

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Found 1 instance in 1 package

Manifest confusion

Supply chain risk

This package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.

Found 1 instance in 1 package

Version published
Weekly downloads
7K
8.73%
Maintainers
0
Weekly downloads
 
Created
Issues
1

npm version

gomplate-npm

Installs gomplate with npm using go-npm.

Publishing

Update version field in package.json with the latest release of gomplate. Then run:

npm publish

FAQs

Package last updated on 06 Jul 2024

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts