PkgRadar

npm · registry.npmjs.org

@gobob/bob-sdk

Remote Dependency Spec: devDependencies.@gobob/tokenlist="github:bob-collective/tokenlist#223e98d85d857ce316fe3a8c3814ed00ddd66556"

Why PkgRadar flagged 5.7.0-rc2

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.@gobob/tokenlist="github:bob-collective/tokenlist#223e98d85d857ce316fe3a8c3814ed00ddd66556" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
5.7.0-rc2Review22026-06-10
5.7.0-rc0Review22026-06-10
5.7.0-rc1Review22026-06-10
5.6.1Review22026-06-04
5.6.0Review22026-05-26
5.5.4Review22026-05-25
5.5.5Review22026-05-25

Block this in CI

PkgRadar gates @gobob/bob-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @gobob/[email protected]