This site is an independent open-source project and is not affiliated with, endorsed by, or sponsored by npm, Inc. or GitHub, Inc. The name “npm” is a registered trademark of npm, Inc., used here solely to describe compatibility and reference publicly available npm package data.
Version Details and Security Vulnerabilities
📦
license
1.0.0
Comparision Betweeen 1.0.0 and 0.0.3
Identify the differences between the current version of the package and the previous one.
Version
Dependencies
9
3
Dev Dependencies
23
0
Peer Dependencies
23
0
Distributed Files
41
N/A
Unpacked Size
36.91 KB
N/A
Security Vulnerabilities
Security Details
Comprehensive list of direct or transitive vulnerabilities for version 1.0.0 of the package license.
All Security Vulnerabilities
All the vulnerabilities related to the version 1.0.0 of the package
Summary:
Prototype Pollution Vulnerability in parse-git-config
Details:
An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function.