react-gestures
Advanced tools
+5
-2
| { | ||
| "name": "react-gestures", | ||
| "version": "0.1.5", | ||
| "version": "0.1.6", | ||
| "description": "React gesture recognizers", | ||
@@ -20,5 +20,8 @@ "main": "index.js", | ||
| "homepage": "https://github.com/bh5-js/react-gestures", | ||
| "dependencies": { | ||
| "dependencies": { | ||
| "babel-runtime": "^5.4.3" | ||
| }, | ||
| "peerDependencies": { | ||
| "react": "^0.13.3" | ||
| }, | ||
| "devDependencies": { | ||
@@ -25,0 +28,0 @@ "babel": "^5.4.3", |
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 1 instance in 1 package
Major refactor
Supply chain riskPackage has recently undergone a major refactor. It may be unstable or indicate significant internal changes. Use caution when updating to versions that include significant changes.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 1 instance in 1 package
No bug tracker
MaintenancePackage does not have a linked bug tracker in package.json.
Found 1 instance in 1 package
No website
QualityPackage does not have a website.
Found 1 instance in 1 package
25138
0.2%0
-100%2
100%