PkgRadar

npm · registry.npmjs.org

@eclipse-che/che-devworkspace-generator

Remote Dependency Spec: devDependencies.license-tool="https://github.com/che-incubator/dash-licenses.git#c09f697ea6336ce82d365654dfeb7ef6e9c84768"

Why PkgRadar flagged 7.118.0

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.license-tool="https://github.com/che-incubator/dash-licenses.git#c09f697ea6336ce82d365654dfeb7ef6e9c84768" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
7.118.0Review42026-06-10
7.118.0-next-18f639aReview42026-06-10
7.118.0-next-19723d1Review42026-06-10
7.118.0-next-abc4b0eReview42026-06-10
7.118.0-next-dfc7693Review22026-06-10

Block this in CI

PkgRadar gates @eclipse-che/che-devworkspace-generator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @eclipse-che/[email protected]