PkgRadar

npm · registry.npmjs.org

@cs2dak/contract

Remote Dependency Spec: dependencies.@rivalhub/rival-rating="github:Starfie1d1272/rival-rating#5d862eb"

Why PkgRadar flagged 0.2.0

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.@rivalhub/rival-rating="github:Starfie1d1272/rival-rating#5d862eb" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0Low risk02026-06-04
0.2.1Low risk02026-06-04
0.2.0Review122026-06-04

Block this in CI

PkgRadar gates @cs2dak/contract (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @cs2dak/[email protected]