+7
-0
@@ -101,2 +101,5 @@ 'use strict' | ||
| parseRange (range) { | ||
| // strip build metadata so it can't bleed into the version | ||
| range = range.replace(BUILDSTRIPRE, '') | ||
| // memoize range parsing for performance. | ||
@@ -227,2 +230,3 @@ // this is a very hot path, and fully deterministic. | ||
| safeRe: re, | ||
| src, | ||
| t, | ||
@@ -235,2 +239,5 @@ comparatorTrimReplace, | ||
| // unbounded global build-metadata stripper used by parseRange | ||
| const BUILDSTRIPRE = new RegExp(src[t.BUILD], 'g') | ||
| const isNullSet = c => c.value === '<0.0.0-0' | ||
@@ -237,0 +244,0 @@ const isAny = c => c.value === '' |
+1
-1
| { | ||
| "name": "semver", | ||
| "version": "7.8.0", | ||
| "version": "7.8.1", | ||
| "description": "The semantic version parser used by npm.", | ||
@@ -5,0 +5,0 @@ "main": "index.js", |
+2
-2
@@ -177,3 +177,3 @@ 'use strict' | ||
| } | ||
| } else if (gt.operator === '>=' && !satisfies(gt.semver, String(c), options)) { | ||
| } else if (gt.operator === '>=' && !c.test(gt.semver)) { | ||
| return false | ||
@@ -196,3 +196,3 @@ } | ||
| } | ||
| } else if (lt.operator === '<=' && !satisfies(lt.semver, String(c), options)) { | ||
| } else if (lt.operator === '<=' && !c.test(lt.semver)) { | ||
| return false | ||
@@ -199,0 +199,0 @@ } |
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 2 instances in 1 package
Long strings
Supply chain riskContains long string literals, which may be a sign of obfuscated or packed code.
Found 1 instance in 1 package
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 2 instances in 1 package
Long strings
Supply chain riskContains long string literals, which may be a sign of obfuscated or packed code.
Found 1 instance in 1 package
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
Found 1 instance in 1 package
100214
0.18%2259
0.22%