PkgRadar

npm · registry.npmjs.org

@bgforge/mls-server

Remote Dependency Spec: optionalDependencies.sslc-emscripten-noderawfs="https://github.com/sfall-team/sslc/releases/download/2026-02-07-11-20-26/wasm-emscripten-node-noderawfs.tar.gz"

Why PkgRadar flagged 3.7.0

SeveritySignalEvidence
highRemote Dependency SpecoptionalDependencies.sslc-emscripten-noderawfs="https://github.com/sfall-team/sslc/releases/download/2026-02-07-11-20-26/wasm-emscripten-node-noderawfs.tar.gz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
3.7.0High risk352026-06-10
3.8.2Review102026-06-05
3.8.1Review102026-06-03

Block this in CI

PkgRadar gates @bgforge/mls-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bgforge/[email protected]