npm · registry.npmjs.org
@automattic/vip
Remote Dependency Spec: dependencies.cli-table="github:automattic/cli-table#7b14232"
Why PkgRadar flagged 2.0.0-dev1
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Dependency Spec | dependencies.cli-table="github:automattic/cli-table#7b14232" · package.json |
| medium | Remote Dependency Spec | devDependencies.eslint-config-wpvip="github:automattic/eslint-config-wpvip#39d3482" · package.json |
| medium | Dependency Changed To Remote Vs Previous | devDependencies.eslint-config-wpvip changed to remote spec in 2.0.0-dev1 vs 1.12.1: "github:automattic/eslint-config-wpvip#39d3482" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.0.0-dev1 | High risk | 33 | 2026-06-20 |
2.0.0-dev2 | Review | 7 | 2026-06-19 |
2.0.0-dev3 | Review | 7 | 2026-06-19 |
4.0.1 | Review | 5 | 2026-06-19 |
4.0.2 | Review | 5 | 2026-06-19 |
4.0.3 | Review | 5 | 2026-06-19 |
4.0.5 | Review | 5 | 2026-06-19 |
Block this in CI
pkgradar gate --ecosystem npm @automattic/[email protected]