PkgRadar

npm · registry.npmjs.org

@bulbthings/bulbthings-sdk

Remote Dependency Spec: dependencies.cross-eventsource="https://github.com/Bulbthings/cross-eventsource.git#0.3.0"

Why PkgRadar flagged 1.3.0

SeveritySignalEvidence
highRemote Dependency Specdependencies.cross-eventsource="https://github.com/Bulbthings/cross-eventsource.git#0.3.0" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.0Review32026-06-15
1.2.0Review32026-06-15
1.2.1Review32026-06-15
1.2.2Review32026-06-15

Block this in CI

PkgRadar gates @bulbthings/bulbthings-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bulbthings/[email protected]