PkgRadar

npm · registry.npmjs.org

@ikko-dev/gitlab-review

Remote Dependency Spec: dependencies.pi-reviewer="github:zeflq/pi-reviewer#afa77eedd9e29eba096baa404a1db81a6509ff7f"

Why PkgRadar flagged 0.1.0

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.pi-reviewer="github:zeflq/pi-reviewer#afa77eedd9e29eba096baa404a1db81a6509ff7f" · package.json
mediumNew Remote Dependency Vs Previousdependencies.pi-reviewer added in 0.1.0 vs 0.0.1: "github:zeflq/pi-reviewer#afa77eedd9e29eba096baa404a1db81a6509ff7f" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.0Review902026-06-17
0.1.1Review232026-06-17
0.7.0Review12026-06-17
0.6.2Review12026-06-09
0.6.1Review12026-06-03
0.6.0Review12026-06-02
0.5.0Review12026-06-02
0.4.2Review12026-06-01
0.4.1Review12026-05-29
0.4.0Review12026-05-28
0.3.11Review12026-05-26
0.3.12Review12026-05-26
0.3.9Low risk02026-05-25
0.3.10Review52026-05-25

Block this in CI

PkgRadar gates @ikko-dev/gitlab-review (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @ikko-dev/[email protected]