leonardojs
Advanced tools
Comparing version 3.1.2 to 3.1.3
{ | ||
"name": "leonardo", | ||
"version": "3.1.0", | ||
"version": "3.1.1", | ||
"homepage": "https://github.com/outbrain/Leonardo", | ||
@@ -5,0 +5,0 @@ "repository": { |
{ | ||
"name": "leonardojs", | ||
"version": "3.1.2", | ||
"version": "3.1.3", | ||
"description": "Leonardo ========", | ||
@@ -5,0 +5,0 @@ "main": "dist/leonardo.js", |
Sorry, the diff of this file is not supported yet
Uses eval
Supply chain riskPackage uses dynamic code execution (e.g., eval()), which is a dangerous practice. This can prevent the code from running in certain environments and increases the risk that the code may contain exploits or malicious behavior.
Found 1 instance in 1 package
Long strings
Supply chain riskContains long string literals, which may be a sign of obfuscated or packed code.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
1327589
74
17312
11
2