terriajs-schema
Advanced tools
Comparing version 0.4.2 to 0.4.3
{ | ||
"name": "terriajs-schema", | ||
"version": "0.4.2", | ||
"version": "0.4.3", | ||
"description": "JSON schema for TerriaJS.", | ||
@@ -20,3 +20,3 @@ "main": "validateSchema.js", | ||
"dependencies": { | ||
"jsonschema": "^1.0.3", | ||
"jsonschema": "terriajs/jsonschema", | ||
"when": "^3.7.7", | ||
@@ -23,0 +23,0 @@ "yargs": "^3.32.0" |
GitHub dependency
Supply chain riskContains a dependency which resolves to a GitHub URL. Dependencies fetched from GitHub specifiers are not immutable can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
493569
1
1
- Removedjsonschema@1.5.0(transitive)