good-guy-http
Advanced tools
Comparing version 1.4.0 to 1.4.1
{ | ||
"name": "good-guy-http", | ||
"version": "1.4.0", | ||
"version": "1.4.1", | ||
"description": "The opinionated sane HTTP client with a good guy approach.", | ||
@@ -19,3 +19,3 @@ "main": "lib/index.js", | ||
"bluebird": "2.10.0", | ||
"circuit-breaker-js": "0.0.1", | ||
"circuit-breaker-js": "Schibsted-Tech-Polska/circuit-breaker-js#v0.0.2", | ||
"request": "2.62.0", | ||
@@ -22,0 +22,0 @@ "underscore": "1.8.3", |
GitHub dependency
Supply chain riskContains a dependency which resolves to a GitHub URL. Dependencies fetched from GitHub specifiers are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
80667
1
4
- Removedcircuit-breaker-js@0.0.1(transitive)
Updatedcircuit-breaker-js@Schibsted-Tech-Polska/circuit-breaker-js#v0.0.2