sarif-codeclimate
Advanced tools
Comparing version
{ | ||
"name": "sarif-codeclimate", | ||
"version": "2.0.1", | ||
"version": "2.1.0", | ||
"description": "Convert your SARIF output into a readable JSON compatible with GitLab Code Climate Tool", | ||
@@ -17,8 +17,3 @@ "main": "out/lib/converter.js", | ||
"format": "prettier --write \"src/**/*.[tj]s\"", | ||
"lint": "tslint -p tsconfig.json", | ||
"prepare": "npm run build", | ||
"prepublishOnly": "npm test && npm run lint", | ||
"preversion": "npm run lint", | ||
"version": "npm run format && git add -A src", | ||
"postversion": "git push && git push --tags" | ||
"lint": "tslint -p tsconfig.json" | ||
}, | ||
@@ -25,0 +20,0 @@ "repository": { |
@@ -0,0 +0,0 @@ <h1 align="center" style="color:#1b4c17"> |
Sorry, the diff of this file is not supported yet
Empty package
Supply chain riskPackage does not contain any code. It may be removed, is name squatting, or the result of a faulty package publish.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 2 instances in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
0
-100%4243
-62.72%3
-72.73%0
-100%2
Infinity%