npm · registry.npmjs.org
@global-engineering-shared/gweb-material-global
no static findings
Scanned versions
Verdict reflects the highest-severity signal, not just the additive score: a single high-severity finding outranks a higher score made up of lower-severity ones, so a lower-scored version can still carry the stronger verdict.
Block this in CI
PkgRadar gates @global-engineering-shared/gweb-material-global (and every other dependency) before it merges. One line in your pipeline:
pkgradar gate --ecosystem npm @global-engineering-shared/[email protected]
Prefer zero config? Install the GitHub App and it gates every pull request automatically — no pipeline edits, no API key.