PkgRadar

npm · registry.npmjs.org

@bablr/language-en-cstml

Remote Dependency Spec: devDependencies.@bablr/eslint-config-base="github:bablr-lang/eslint-config-base#23b94fb3bdfdbc3ac7ed9cb58d7979d8f07dce2b"

Why PkgRadar flagged 0.13.0

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.@bablr/eslint-config-base="github:bablr-lang/eslint-config-base#23b94fb3bdfdbc3ac7ed9cb58d7979d8f07dce2b" · package.json
mediumDependency Changed To Remote Vs PreviousdevDependencies.@bablr/eslint-config-base changed to remote spec in 0.13.0 vs 0.12.6: "github:bablr-lang/eslint-config-base#23b94fb3bdfdbc3ac7ed9cb58d7979d8f07dce2b" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.13.0Review162026-06-03
0.13.1Review82026-05-24

Related campaigns

Block this in CI

PkgRadar gates @bablr/language-en-cstml (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bablr/[email protected]