PkgRadar

npm · registry.npmjs.org

@h-rig/rig-extension

Remote Dependency Spec, Dependency Changed To Remote Vs Previous

Why PkgRadar flagged 0.0.6-alpha.135

SeveritySignalEvidence
highRemote Dependency Specpackage.json
highDependency Changed To Remote Vs Previouspackage.json

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.6-alpha.135High risk242026-06-23
0.0.6-alpha.134Low risk02026-06-23
0.0.6-alpha.133Low risk02026-06-23
0.0.6-alpha.132Low risk02026-06-22
0.0.6-alpha.131Low risk02026-06-22
0.0.6-alpha.130Low risk02026-06-22
0.0.6-alpha.129Low risk02026-06-22
0.0.6-alpha.128Low risk02026-06-21
0.0.6-alpha.127Low risk02026-06-21
0.0.6-alpha.126Low risk02026-06-21
0.0.6-alpha.124Low risk02026-06-21
0.0.6-alpha.125Low risk02026-06-21
0.0.6-alpha.123Low risk02026-06-21
0.0.6-alpha.122Low risk02026-06-21
0.0.6-alpha.121Low risk02026-06-21
0.0.6-alpha.120Low risk02026-06-21
0.0.6-alpha.119Low risk02026-06-21
0.0.6-alpha.103Low risk02026-06-19
0.0.6-alpha.100Low risk02026-06-19
0.0.6-alpha.94Low risk02026-06-19
0.0.6-alpha.93Low risk02026-06-19
0.0.6-alpha.91Low risk02026-06-19
0.0.6-alpha.92Low risk02026-06-19

Block this in CI

PkgRadar gates @h-rig/rig-extension (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @h-rig/[email protected]