Comparing version 0.0.4 to 0.0.5
{ | ||
"name": "ng", | ||
"version": "0.0.4", | ||
"version": "0.0.5", | ||
"dependencies": { | ||
"angular": "https://github.com/angular/angular.js/tarball/v1.2.5" | ||
"angular": "http://ajax.googleapis.com/ajax/libs/angularjs/1.2.6/angular.js" | ||
} | ||
} |
HTTP dependency
Supply chain riskContains a dependency which resolves to a remote HTTP URL which could be used to inject untrusted code and reduce overall package reliability.
Found 1 instance in 1 package
AI-detected possible typosquat
Supply chain riskAI has identified this package as a potential typosquat of a more popular package. This suggests that the package may be intentionally mimicking another package's name, description, or other metadata.
Found 1 instance in 1 package
HTTP dependency
Supply chain riskContains a dependency which resolves to a remote HTTP URL which could be used to inject untrusted code and reduce overall package reliability.
Found 1 instance in 1 package
3196
2