PkgRadar

npm · registry.npmjs.org

@backstage/create-app

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.8.4

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/lib/tasks.cjs.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.4Review32026-06-16
0.0.0-nightly-20260616032439Review32026-06-16
0.0.0-nightly-20260615032517Review32026-06-15
0.0.0-nightly-20260614032343Review32026-06-15
0.0.0-nightly-20260613032133Review32026-06-13
0.0.0-nightly-20260612032440Review32026-06-13
0.0.0-nightly-20260611032059Review32026-06-11
0.0.0-nightly-20260610032156Review32026-06-10
0.8.4-next.2Review32026-06-09
0.0.0-nightly-20260609032118Review32026-06-09
0.0.0-nightly-20260608032505Review32026-06-09
0.0.0-nightly-20260607032244Review32026-06-07
0.0.0-nightly-20260606031950Review32026-06-06
0.0.0-nightly-20260605032312Review32026-06-05
0.0.0-nightly-20260604032348Review32026-06-04
0.0.0-nightly-20260603032450Review32026-06-03
0.8.4-next.1Review32026-06-02
0.0.0-nightly-20260602032639Review32026-06-02
0.0.0-nightly-20260601032430Review32026-06-01
0.0.0-nightly-20260531032321Review32026-05-31
0.0.0-nightly-20260530032139Review32026-05-30
0.0.0-nightly-20260529032432Review32026-05-29
0.0.0-nightly-20260528032551Review92026-05-28
0.0.0-nightly-20260527032423Review92026-05-27
0.8.4-next.0Review92026-05-26
0.8.3Review92026-05-26

Block this in CI

PkgRadar gates @backstage/create-app (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @backstage/[email protected]