PkgRadar

npm · registry.npmjs.org

@brave/brave-ui

Remote Dependency Spec: dependencies.@balajmarius/svg2jsx="github:brave/svg2jsx#507bc7e3782f838fc28af639bfcd24bb4435a218"

Why PkgRadar flagged 0.40.5

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.@balajmarius/svg2jsx="github:brave/svg2jsx#507bc7e3782f838fc28af639bfcd24bb4435a218" · package.json
mediumNew Remote Dependency Vs Previousdependencies.@balajmarius/svg2jsx added in 0.40.5 vs 0.40.4: "github:brave/svg2jsx#507bc7e3782f838fc28af639bfcd24bb4435a218" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.40.3Low risk02026-06-18
0.40.4Low risk02026-06-18
0.40.5Review242026-06-18
0.40.6Low risk02026-06-18

Block this in CI

PkgRadar gates @brave/brave-ui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @brave/[email protected]