This site is an independent open-source project and is not affiliated with, endorsed by, or sponsored by npm, Inc. or GitHub, Inc. The name “npm” is a registered trademark of npm, Inc., used here solely to describe compatibility and reference publicly available npm package data.
Version Details and Security Vulnerabilities
📦
sane
1.4.0
Comparision Betweeen 1.4.0 and 1.3.5
Identify the differences between the current version of the package and the previous one.
Version
Dependencies
6
6
Dev Dependencies
4
0
Peer Dependencies
4
0
Distributed Files
N/A
N/A
Unpacked Size
N/A
N/A
Security Vulnerabilities
Security Details
Comprehensive list of direct or transitive vulnerabilities for version 1.4.0 of the package sane.
All Security Vulnerabilities
All the vulnerabilities related to the version 1.4.0 of the package
Summary:
Prototype Pollution in merge
Details:
All versions of package merge <2.1.1 are vulnerable to Prototype Pollution via _recursiveMerge .