Comparing version 0.0.9 to 0.1.0
{ | ||
"name": "wraplog", | ||
"license": "BSD-3-Clause", | ||
"version": "0.0.9", | ||
"version": "0.1.0", | ||
"dependencies": { | ||
"winston": "^3.2.1", | ||
"winston-syslog": "git+https://github.com/faust64/winston-syslog.git", | ||
"winston-syslog": "^2.4.4", | ||
"winston-transport": "^4.3.0" | ||
}, | ||
"devDependencies": { | ||
"mocha": "^6.2.2" | ||
"mocha": "^7.1.1" | ||
}, | ||
"description": "logging library", | ||
"engines": { | ||
"node": "6.9.1" | ||
"node": "10.17.0" | ||
}, | ||
@@ -17,0 +17,0 @@ "repository": "https://github.com/faust64/logger", |
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable and can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
0
7777
+ Addedbindings@1.5.0(transitive)
+ Addedfile-uri-to-path@1.0.0(transitive)
+ Addedglossy@0.1.7(transitive)
+ Addednan@2.22.0(transitive)
+ Addedunix-dgram@2.0.6(transitive)
+ Addedwinston-syslog@2.7.1(transitive)
Updatedwinston-syslog@^2.4.4