PkgRadar

npm · registry.npmjs.org

@ibm/itest

Remote Dependency Spec: devDependencies.vscode-ibmi="github:halcyon-tech/vscode-ibmi"

Why PkgRadar flagged 1.3.2

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.vscode-ibmi="github:halcyon-tech/vscode-ibmi" · package.json
mediumRemote Dependency SpecdevDependencies.vscode-rpgle="github:halcyon-tech/vscode-rpgle" · package.json
mediumNew Remote Dependency Vs PreviousdevDependencies.vscode-ibmi added in 1.3.2 vs 1.3.1: "github:halcyon-tech/vscode-ibmi" · package.json
mediumNew Remote Dependency Vs PreviousdevDependencies.vscode-rpgle added in 1.3.2 vs 1.3.1: "github:halcyon-tech/vscode-rpgle" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.2Review322026-06-06
1.3.3Review42026-06-06

Block this in CI

PkgRadar gates @ibm/itest (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @ibm/[email protected]