http-signature
Advanced tools
Comparing version 1.0.0 to 1.0.1
# node-http-signature changelog | ||
## 1.0.0 (not yet released) | ||
## 1.0.1 | ||
- Bump minimum version of `sshpk` dependency, to include fixes for | ||
whitespace tolerance in key parsing. | ||
## 1.0.0 | ||
- First semver release. | ||
@@ -6,0 +11,0 @@ - #36: Ensure verifySignature does not leak useful timing information |
{ | ||
"name": "http-signature", | ||
"description": "Reference implementation of Joyent's HTTP Signature scheme.", | ||
"version": "1.0.0", | ||
"version": "1.0.1", | ||
"license": "MIT", | ||
@@ -33,3 +33,3 @@ "author": "Joyent, Inc", | ||
"jsprim": "^1.2.0", | ||
"sshpk": "^1.4.0" | ||
"sshpk": "^1.4.6" | ||
}, | ||
@@ -36,0 +36,0 @@ "peerDependencies": { |
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
Major refactor
Supply chain riskPackage has recently undergone a major refactor. It may be unstable or indicate significant internal changes. Use caution when updating to versions that include significant changes.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
45433
1
Updatedsshpk@^1.4.6