3 ms·
My guess is that the npm package itself got hijacked? The latest version on npm is v11.1.0 (updated 3 days ago) while master on GitHub is v10.1.0 (updated 9 mon
by jaxrtech 5y ago
My guess is that the npm package itself got hijacked? The latest version on npm is v11.1.0 (updated 3 days ago) while master on GitHub is v10.1.0 (updated 9 months ago).
- jeroenhd 5y agoNo, this was intentional. The author added the peacenotwar package to the dependencies and bumped the version a bunch of times to trigger automatic dependency updates. This is why you should pin dependencies, but good luck keeping up with that in modern Javascript dependency hell where every framework pulls in half a gigabyte of dependencies.