PkgRadar

npm · registry.npmjs.org

@inco/lightning

Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 6 dependency(ies) (2 with loose/empty version specs) — dependency-confusion / install-chain loader shape

Why PkgRadar flagged 0.1.30

SeveritySignalEvidence
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 6 dependency(ies) (2 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json
highRemote Dependency Specdependencies.ds-test="https://github.com/dapphub/ds-test" · package.json
highRemote Dependency Specdependencies.forge-std="https://github.com/foundry-rs/forge-std" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0Review152026-06-13
1.0.0-rc-13Review152026-06-12
1.0.0-rc-12Review152026-06-12
1.0.0-rc-11Review152026-06-12
0.1.30High risk192026-06-11
0.7.12High risk252026-06-11
0.1.29High risk192026-06-11
1.0.0-rc-8High risk252026-06-11
1.0.0-rc-7High risk252026-06-11
1.0.0-rc-6High risk252026-06-10
1.0.0-rc-5Review182026-05-29
1.0.0-rc-4Review182026-05-29
1.0.0-rc-2Review182026-05-27
1.0.0-rc-3Review182026-05-27

Block this in CI

PkgRadar gates @inco/lightning (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @inco/[email protected]