PkgRadar

npm · registry.npmjs.org

@aave-dao/toolbox

Remote Dependency Spec: devDependencies.@aave-dao/aave-delivery-infrastructure="github:aave-dao/aave-delivery-infrastructure"

Why PkgRadar flagged 0.5.0

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.@aave-dao/aave-delivery-infrastructure="github:aave-dao/aave-delivery-infrastructure" · package.json
mediumRemote Dependency SpecdevDependencies.@aave-dao/aave-governance-v3="github:aave-dao/aave-governance-v3" · package.json
mediumRemote Dependency SpecdevDependencies.@aave-dao/aave-price-feeds="github:aave-dao/aave-price-feeds" · package.json
mediumRemote Dependency SpecdevDependencies.@aave-dao/solidity-utils="github:aave-dao/solidity-utils" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.0Review92026-06-03
0.4.0Review322026-06-02

Block this in CI

PkgRadar gates @aave-dao/toolbox (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @aave-dao/[email protected]