sockit-to-me
Advanced tools
Comparing version 0.1.4 to 0.1.6
{ | ||
"name": "sockit-to-me", | ||
"version": "0.1.4", | ||
"version": "0.1.6", | ||
"author": "Ghislain 'Aus' Lacroix <aus@mozilla.com>", | ||
@@ -11,4 +11,4 @@ "description": "A synchronous socket API for node.js.", | ||
"test": "mocha", | ||
"preinstall": ": noop", | ||
"install": "node tools/copy.js || node-gyp configure build" | ||
"preinstall": "./tools/info.js || echo \"[sockit-to-me] OK\"", | ||
"install": "./tools/info.js || ./tools/copy.js || node-gyp configure build" | ||
}, | ||
@@ -15,0 +15,0 @@ "dependencies": {}, |
@@ -6,3 +6,3 @@ sockit-to-me | ||
[![Build Status](https://travis-ci.org/nullaus/sockit-to-me.png)](https://travis-ci.org/nullaus/sockit-to-me) | ||
[![Build Status](https://travis-ci.org/mozilla-b2g/sockit-to-me.png)](https://travis-ci.org/mozilla-b2g/sockit-to-me) | ||
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
Install scripts
Supply chain riskInstall scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 1 instance in 1 package
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
Install scripts
Supply chain riskInstall scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
195753
36
351
1