PkgRadar

npm · registry.npmjs.org

@dbos-inc/otel

Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 11 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape

Why PkgRadar flagged 4.20.10-preview

SeveritySignalEvidence
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 11 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
4.20.10-previewReview102026-06-10
4.20.9-previewReview102026-06-10
4.20.8-previewReview102026-06-09
4.20.7-previewReview102026-06-08
4.20.5-previewReview102026-06-05
4.20.3-previewReview102026-06-02
4.19.8Review102026-06-01
4.19.7-previewLow risk02026-05-29
4.19.5-previewLow risk02026-05-26
4.19.6-previewLow risk02026-05-26

Block this in CI

PkgRadar gates @dbos-inc/otel (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @dbos-inc/[email protected]