PkgRadar

npm · registry.npmjs.org

@h-rig/core

Remote Dependency Spec: dependencies.effect="https://pkg.pr.new/Effect-TS/effect-smol/effect@8881a9b"

Why PkgRadar flagged 0.0.5-alpha.0

SeveritySignalEvidence
highRemote Dependency Specdependencies.effect="https://pkg.pr.new/Effect-TS/effect-smol/effect@8881a9b" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.6-alpha.22Low risk02026-06-08
0.0.6-alpha.21Low risk02026-06-08
0.0.6-alpha.20Low risk02026-06-08
0.0.6-alpha.19Low risk02026-06-08
0.0.6-alpha.18Low risk02026-06-08
0.0.6-alpha.17Low risk02026-06-08
0.0.6-alpha.15Low risk02026-06-08
0.0.6-alpha.16Low risk02026-06-08
0.0.6-alpha.14Low risk02026-06-08
0.0.6-alpha.13Low risk02026-06-08
0.0.6-alpha.12Low risk02026-06-08
0.0.6-alpha.11Low risk02026-06-08
0.0.6-alpha.10Low risk02026-06-08
0.0.6-alpha.9Low risk02026-06-08
0.0.6-alpha.8Low risk02026-06-08
0.0.6-alpha.7Low risk02026-06-08
0.0.6-alpha.6Low risk02026-06-08
0.0.6-alpha.5Low risk02026-06-08
0.0.6-alpha.4Low risk02026-06-08
0.0.6-alpha.3Low risk02026-06-08
0.0.6-alpha.2Low risk02026-06-07
0.0.6-alpha.1Low risk02026-06-07
0.0.6-alpha.0Low risk02026-06-07
0.0.5-alpha.0High risk122026-06-07

Block this in CI

PkgRadar gates @h-rig/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @h-rig/[email protected]