oe-npm-keyword
Advanced tools
Comparing version 1.5.0 to 1.5.1
{ | ||
"name": "oe-npm-keyword", | ||
"version": "1.5.0", | ||
"version": "1.5.1", | ||
"description": "Get a list of npm packages with a certain keyword", | ||
@@ -41,13 +41,13 @@ "license": "MIT", | ||
"dependencies": { | ||
"https-proxy-agent": "^1.0.0", | ||
"node-fetch": "^1.6.3", | ||
"object-assign": "^4.0.1", | ||
"pinkie-promise": "^2.0.0", | ||
"rc": "^1.2.1", | ||
"registry-url": "^3.0.3" | ||
"https-proxy-agent": "2.2.4", | ||
"node-fetch": "1.7.3", | ||
"object-assign": "4.1.1", | ||
"pinkie-promise": "2.0.1", | ||
"rc": "1.2.8", | ||
"registry-url": "3.1.0" | ||
}, | ||
"devDependencies": { | ||
"ava": "*", | ||
"xo": "*" | ||
"ava": "3.0.0", | ||
"xo": "0.25.3" | ||
} | ||
} |
AI-detected possible typosquat
Supply chain riskAI has identified this package as a potential typosquat of a more popular package. This suggests that the package may be intentionally mimicking another package's name, description, or other metadata.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
4153
+ Addedagent-base@4.3.0(transitive)
+ Addeddebug@3.2.7(transitive)
+ Addedes6-promise@4.2.8(transitive)
+ Addedes6-promisify@5.0.0(transitive)
+ Addedhttps-proxy-agent@2.2.4(transitive)
+ Addedms@2.1.3(transitive)
- Removedagent-base@2.1.1(transitive)
- Removeddebug@2.6.9(transitive)
- Removedextend@3.0.2(transitive)
- Removedhttps-proxy-agent@1.0.0(transitive)
- Removedms@2.0.0(transitive)
- Removedsemver@5.0.3(transitive)
Updatedhttps-proxy-agent@2.2.4
Updatednode-fetch@1.7.3
Updatedobject-assign@4.1.1
Updatedpinkie-promise@2.0.1
Updatedrc@1.2.8
Updatedregistry-url@3.1.0