PkgRadar

npm · registry.npmjs.org

@bondsports/calendar

Manifest Codeless Dependency Stub

Why PkgRadar flagged 3.0.15-noam

SeveritySignalEvidence
mediumManifest Codeless Dependency Stub

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.8Low risk02026-06-28
1.2.1-yoav52Low risk02026-06-28
1.2.1-yoav54Low risk02026-06-28
3.0.15-noamReview72026-06-28
3.0.17Low risk02026-06-28
3.0.18Low risk02026-06-28
3.0.19Low risk02026-06-28
3.0.19-gittyLow risk02026-06-28

Block this in CI

PkgRadar gates @bondsports/calendar (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bondsports/[email protected]
@bondsports/calendar — npm security scan | PkgRadar