PkgRadar

npm · registry.npmjs.org

@castlabs/prestoplay-react-components

Remote Dependency Spec: devDependencies.eslint-plugin-import="github:fingerartur/eslint-plugin-import"

Why PkgRadar flagged 0.9.3

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.eslint-plugin-import="github:fingerartur/eslint-plugin-import" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.3Review42026-06-09
0.9.3-beta.3Review42026-06-09
0.9.3-beta.4Review42026-06-09
0.9.3-beta.5Review42026-06-09

Block this in CI

PkgRadar gates @castlabs/prestoplay-react-components (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @castlabs/[email protected]