PkgRadar

npm · registry.npmjs.org

@bonlineza/b-lib

Remote Dependency Spec: dependencies.react-dates="https://github.com/bonlineza/react-dates#v16.0.1-showBeforeTodayDifferently-lib"

Why PkgRadar flagged 1.0.3

SeveritySignalEvidence
highRemote Dependency Specdependencies.react-dates="https://github.com/bonlineza/react-dates#v16.0.1-showBeforeTodayDifferently-lib" · package.json
highRemote Dependency Specdependencies.react-pdf-js="https://github.com/robguy21/react-pdf-js#v4.1.0" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.3High risk122026-06-15
3.2.1High risk122026-06-15
3.2.2High risk122026-06-15
4.0.0High risk62026-06-15
4.0.1High risk62026-06-15

Block this in CI

PkgRadar gates @bonlineza/b-lib (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bonlineza/[email protected]