npm · registry.npmjs.org
@handsontable/js-xlsx
Remote Dependency Spec: dependencies.from-xml="git+https://github.com/handsontable/from-xml.git"
Why PkgRadar flagged 100.0.12-d0a70e4
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Dependency Spec | dependencies.from-xml="git+https://github.com/handsontable/from-xml.git" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
100.0.12-d0a70e4 | Review | 6 | 2026-06-16 |
100.0.13 | Review | 6 | 2026-06-16 |
100.0.13-7a1c458 | Review | 6 | 2026-06-16 |
100.0.13-ff6e7dc | Review | 6 | 2026-06-16 |
Block this in CI
pkgradar gate --ecosystem npm @handsontable/[email protected]