Comparing version 0.4.1 to 0.4.2
@@ -81,2 +81,4 @@ | ||
if (options.inResponseTo) | ||
confirmationData[0].setAttribute('InResponseTo', options.inResponseTo); | ||
@@ -83,0 +85,0 @@ if (options.attributes) { |
{ | ||
"name": "saml", | ||
"version": "0.4.1", | ||
"version": "0.4.2", | ||
"devDependencies": { | ||
@@ -17,3 +17,3 @@ "mocha": "*", | ||
"dependencies": { | ||
"xml-crypto": "git://github.com/auth0/xml-crypto", | ||
"xml-crypto": "0.0.13", | ||
"xmldom": "=0.1.15", | ||
@@ -20,0 +20,0 @@ "moment": "~1.7.2" |
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
32136
561
0
0
+ Addedxml-crypto@0.0.13(transitive)
Updatedxml-crypto@0.0.13