+2
-2
| { | ||
| "name": "tweetcat", | ||
| "version": "0.0.6", | ||
| "version": "0.0.7", | ||
| "description": "p2p pipe across the internet using Twitter as a transport stream", | ||
@@ -37,3 +37,3 @@ "main": "index.js", | ||
| "mkdirp": "^0.5.1", | ||
| "opn": "git://github.com/watson/opn.git#no-wait", | ||
| "opn": "^3.0.0", | ||
| "read": "^1.0.6", | ||
@@ -40,0 +40,0 @@ "through2": "^2.0.0", |
Dynamic require
Supply chain riskDynamic require can indicate the package is performing dangerous or unsafe dynamic code execution.
Found 1 instance in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable and can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
Dynamic require
Supply chain riskDynamic require can indicate the package is performing dangerous or unsafe dynamic code execution.
Found 1 instance in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
0
-100%10663
-0.31%+ Added
+ Added
Updated