Comparing version 1.2.4 to 1.2.5
@@ -5,3 +5,3 @@ var {moreSalting} = require('./algos/somersault') | ||
const input = string; | ||
var salt = parseInt(pass); | ||
var salt = parseInt(pass) + process.env.SECRET; | ||
@@ -35,3 +35,3 @@ var extraSalt = moreSalting(salt); | ||
const inputRev = string; | ||
var saltRev = parseInt(pass); | ||
var saltRev = parseInt(pass) - process.env.SECRET; | ||
@@ -38,0 +38,0 @@ var extraSaltRev = moreSalting(saltRev); |
{ | ||
"name": "keyhasher", | ||
"version": "1.2.4", | ||
"version": "1.2.5", | ||
"description": "", | ||
@@ -22,3 +22,6 @@ "main": "encrypthashop.js", | ||
"author": "igeek", | ||
"license": "MIT" | ||
"license": "MIT", | ||
"dependencies": { | ||
"dotenv": "^16.0.2" | ||
} | ||
} |
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 1 instance in 1 package
38460
8
178
1
2
+ Addeddotenv@^16.0.2
+ Addeddotenv@16.4.7(transitive)