Comparing version 0.2.6 to 0.2.7
{ | ||
"name": "lop", | ||
"version": "0.2.6", | ||
"version": "0.2.7", | ||
"dependencies": { | ||
"underscore": "latest", | ||
"underscore": "~1.4.4", | ||
"option": "0.2.x", | ||
"duck": "git://github.com/mwilliamson/duck.js.git" | ||
"duck": "~0.1.10" | ||
}, | ||
"devDependencies": { | ||
"nodeunit": "latest" | ||
"nodeunit": "~0.8.0" | ||
} | ||
} |
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
0
0
70508
+ Addedduck@0.1.12(transitive)
+ Addedunderscore@1.4.4(transitive)
Updatedduck@~0.1.10
Updatedunderscore@~1.4.4