rox-react-native
Advanced tools
Comparing version 1.2.10 to 2.0.2
{ | ||
"name": "rox-react-native", | ||
"version": "1.2.10", | ||
"version": "2.0.2", | ||
"description": "Rollout.io ROX JS SDK Client", | ||
@@ -45,3 +45,3 @@ "author": "Rollout.io <support@rollout.io>", | ||
"dependencies": { | ||
"rox-base": "^1.2.9" | ||
"rox-base": "^2.0.2" | ||
}, | ||
@@ -70,6 +70,12 @@ "devDependencies": { | ||
"jest": { | ||
"moduleFileExtensions": ["js"], | ||
"moduleDirectories": ["node_modules"], | ||
"transformIgnorePatterns": ["/node_modules/(?!rox-base).+\\.js$"] | ||
"moduleFileExtensions": [ | ||
"js" | ||
], | ||
"moduleDirectories": [ | ||
"node_modules" | ||
], | ||
"transformIgnorePatterns": [ | ||
"/node_modules/(?!rox-base).+\\.js$" | ||
] | ||
} | ||
} |
Sorry, the diff of this file is too big to display
Sorry, the diff of this file is not supported yet
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
Uses eval
Supply chain riskPackage uses dynamic code execution (e.g., eval()), which is a dangerous practice. This can prevent the code from running in certain environments and increases the risk that the code may contain exploits or malicious behavior.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 3 instances in 1 package
6
700508
8746
+ Addedrox-base@2.3.7(transitive)
- Removedaxios@0.17.1(transitive)
- Removedcall-bind-apply-helpers@1.0.2(transitive)
- Removedcall-bound@1.0.3(transitive)
- Removedcharenc@0.0.2(transitive)
- Removedcrypt@0.0.2(transitive)
- Removeddunder-proto@1.0.1(transitive)
- Removedes-define-property@1.0.1(transitive)
- Removedes-errors@1.3.0(transitive)
- Removedes-object-atoms@1.1.1(transitive)
- Removedfollow-redirects@1.15.9(transitive)
- Removedfunction-bind@1.1.2(transitive)
- Removedget-intrinsic@1.2.7(transitive)
- Removedget-proto@1.0.1(transitive)
- Removedgopd@1.2.0(transitive)
- Removedhas-symbols@1.1.0(transitive)
- Removedhasown@2.0.2(transitive)
- Removedis-buffer@1.1.6(transitive)
- Removedlodash.clonedeep@4.5.0(transitive)
- Removedloglevel@1.9.2(transitive)
- Removedlscache@1.3.2(transitive)
- Removedmath-intrinsics@1.1.0(transitive)
- Removedmd5@2.3.0(transitive)
- Removedobject-inspect@1.13.4(transitive)
- Removedqs@6.14.0(transitive)
- Removedrox-base@1.2.9(transitive)
- Removedside-channel@1.1.0(transitive)
- Removedside-channel-list@1.0.0(transitive)
- Removedside-channel-map@1.0.1(transitive)
- Removedside-channel-weakmap@1.0.2(transitive)
- Removeduuid@3.4.0(transitive)
Updatedrox-base@^2.0.2