Comparing version 1.1.3 to 1.1.4
{ | ||
"name": "utxo-lib", | ||
"version": "1.1.3", | ||
"version": "1.1.4", | ||
"description": "Client-side Bitcoin JavaScript library", | ||
@@ -50,3 +50,3 @@ "main": "./dist/src/index.js", | ||
"@bitgo/blake2b": "^3.2.1", | ||
"@brandonblack/musig": "https://github.com/Mustafa-Agha/musig-js.git", | ||
"@brandonblack/musig": "^0.0.1-alpha.0", | ||
"@noble/secp256k1": "1.6.3", | ||
@@ -53,0 +53,0 @@ "bech32": "^2.0.0", |
HTTP dependency
Supply chain riskContains a dependency which resolves to a remote HTTP URL which could be used to inject untrusted code and reduce overall package reliability.
Found 1 instance in 1 package
Manifest confusion
Supply chain riskThis package has inconsistent metadata. This could be malicious or caused by an error when publishing the package.
Found 1 instance in 1 package
0
0
1533859
+ Added@brandonblack/musig@0.0.1-alpha.1(transitive)