+1
-0
@@ -345,2 +345,3 @@ const crypto = require('node:crypto') | ||
| mani._attestations = dist.attestations | ||
| mani._attestationBundles = attestations | ||
| } else { | ||
@@ -347,0 +348,0 @@ mani._attestations = dist.attestations |
+3
-3
| { | ||
| "name": "pacote", | ||
| "version": "21.4.0", | ||
| "version": "21.5.0", | ||
| "description": "JavaScript package downloader", | ||
@@ -31,3 +31,3 @@ "author": "GitHub Inc.", | ||
| "@npmcli/eslint-config": "^6.0.0", | ||
| "@npmcli/template-oss": "4.28.0", | ||
| "@npmcli/template-oss": "4.29.0", | ||
| "hosted-git-info": "^9.0.0", | ||
@@ -77,3 +77,3 @@ "mutate-fs": "^2.1.1", | ||
| "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-oss. Edits may be overwritten.", | ||
| "version": "4.28.0", | ||
| "version": "4.29.0", | ||
| "windowsCI": false, | ||
@@ -80,0 +80,0 @@ "publish": "true" |
Network access
Supply chain riskThis module accesses the network.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 4 instances in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
Long strings
Supply chain riskContains long string literals, which may be a sign of obfuscated or packed code.
Found 1 instance in 1 package
Network access
Supply chain riskThis module accesses the network.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 4 instances in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
Long strings
Supply chain riskContains long string literals, which may be a sign of obfuscated or packed code.
Found 1 instance in 1 package
76680
0.07%1603
0.06%