PkgRadar

npm · registry.npmjs.org

@itcase/forms

Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 25 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape

Why PkgRadar flagged 1.1.100

SeveritySignalEvidence
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 25 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.103Low risk02026-06-15
1.1.101Low risk02026-06-15
1.1.100Review72026-06-15
1.1.99Low risk02026-06-14
1.1.98Low risk02026-06-14
1.1.96Low risk02026-06-11
1.1.58Low risk02026-06-10
1.1.59Low risk02026-06-10
1.1.57Low risk02026-06-10
1.1.95Low risk02026-06-10
1.1.94Low risk02026-06-03
1.1.93Low risk02026-06-02
1.1.92Low risk02026-06-02
1.1.91Low risk02026-06-02
1.1.90Low risk02026-05-29
1.1.89Low risk02026-05-29
1.1.87Low risk02026-05-27
1.1.88Low risk02026-05-27
1.1.86Low risk02026-05-25
1.1.85Low risk02026-05-25
1.1.83Low risk02026-05-25
1.1.84Low risk02026-05-25
1.1.81Low risk02026-05-25
1.1.79Low risk02026-05-25
1.1.80Low risk02026-05-25
1.1.77Low risk02026-05-25
1.1.76Low risk02026-05-25
1.1.75Low risk02026-05-25

Block this in CI

PkgRadar gates @itcase/forms (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @itcase/[email protected]