+5
-3
| { | ||
| "name": "libinkle", | ||
| "version": "0.0.1", | ||
| "version": "0.0.2", | ||
| "description": "A light library for inkle writer stories", | ||
@@ -16,8 +16,10 @@ "main": "index.js", | ||
| "license": "GPL-3.0", | ||
| "dependencies": { | ||
| "devDependencies": { | ||
| "chai": "^4.1.2", | ||
| "keypress": "git://github.com/rahulsonwalkar/keypress#d1ea9ba1d9db5957b73cc438c80a908df23325a9", | ||
| "lodash": "^4.17.4", | ||
| "mocha": "^4.0.1" | ||
| }, | ||
| "dependencies": { | ||
| "lodash": "^4.17.4" | ||
| } | ||
| } |
+3
-0
@@ -67,4 +67,7 @@ # Why libinkle? | ||
| [ ] Error management is rather inexistant | ||
| [x] Flags and if conditions | ||
| [ ] Sections | ||
| [x] Images | ||
@@ -71,0 +74,0 @@ |
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable and can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
125041
0.02%1
-75%76
4.11%0
-100%0
-100%3
Infinity%- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed
- Removed