cclr-components
v2.0.0
Published
Security research placeholder. This name matched an unregistered internal dependency; registered defensively pending vendor response. Not a functional library.
Maintainers
Readme
cclr-components
This is not a functional library. Do not add it as a dependency.
What this is
This package name matched a dependency referenced by a third party application but not registered on the public npm registry. That gap allows a dependency confusion attack: a build that resolves the name from public npm instead of a private registry would install whatever any stranger published under it.
I registered the name defensively so it could not be claimed by an unrelated party, and reported the issue to the vendor through their security programme.
