PkgRadar

npm · registry.npmjs.org

@bonniernews/b0rker

Remote Dependency Spec: dependencies.lu-logger="github:BonnierNews/lu-logger#semver:^8.1.0"

Why PkgRadar flagged 10.2.1

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.lu-logger="github:BonnierNews/lu-logger#semver:^8.1.0" · package.json
mediumDependency Changed To Remote Vs Previousdependencies.lu-logger changed to remote spec in 10.2.1 vs 10.2.0: "github:BonnierNews/lu-logger#semver:^8.1.0" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
10.2.1Review242026-06-16
10.3.0Review62026-06-16
11.0.0Review62026-06-01
11.1.0Review62026-06-01

Block this in CI

PkgRadar gates @bonniernews/b0rker (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bonniernews/[email protected]