PkgRadar

npm · registry.npmjs.org

@jahia/jcontent

Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 60 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape

Why PkgRadar flagged 3.7.0-SNAPSHOT.1780420934374

SeveritySignalEvidence
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 60 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
3.7.0-SNAPSHOT.1781273416026Low risk02026-06-12
3.7.0-SNAPSHOT.1781269582998Low risk02026-06-12
3.7.0-SNAPSHOT.1781194700544Low risk02026-06-12
3.7.0-SNAPSHOT.1781181444750Low risk02026-06-11
3.7.0-SNAPSHOT.1781180117841Low risk02026-06-11
3.7.0-SNAPSHOT.1781163292457Low risk02026-06-11
3.7.0-SNAPSHOT.1781162650500Low risk02026-06-11
3.7.0-SNAPSHOT.1781117648863Low risk02026-06-10
3.7.0-SNAPSHOT.1781110748095Low risk02026-06-10
3.7.0-SNAPSHOT.1781103203022Low risk02026-06-10
3.7.0-SNAPSHOT.1781101278657Low risk02026-06-10
3.6.0-SNAPSHOT.1769586664679Low risk02026-06-10
3.7.0-SNAPSHOT.1781008518126Low risk02026-06-10
3.7.0-SNAPSHOT.1781094243445Low risk02026-06-10
3.7.0-SNAPSHOT.1781008454146Low risk02026-06-09
3.7.0-SNAPSHOT.1781005960240Low risk02026-06-09
3.7.0-SNAPSHOT.1780934818480Low risk02026-06-08
3.7.0-SNAPSHOT.1780850103202Low risk02026-06-07
3.7.0-SNAPSHOT.1780686224151Low risk02026-06-05
3.7.0-SNAPSHOT.1780673657063Low risk02026-06-05
3.7.0-SNAPSHOT.1780670794939Low risk02026-06-05
3.7.0-SNAPSHOT.1780666831837Low risk02026-06-05
3.7.0-SNAPSHOT.1780665041162Low risk02026-06-05
3.7.0-SNAPSHOT.1780660923031Low risk02026-06-05
3.7.0-SNAPSHOT.1780491640098Low risk02026-06-03
3.7.0-SNAPSHOT.1780420934374Review42026-06-02
3.7.0-SNAPSHOT.1780337988124Review42026-06-01
3.7.0-SNAPSHOT.1779972091861Low risk02026-05-28
3.7.0-SNAPSHOT.1779979587278Low risk02026-05-28
3.7.0-SNAPSHOT.1779893500860Low risk02026-05-27
3.7.0-SNAPSHOT.1779892326868Low risk02026-05-27
3.7.0-SNAPSHOT.1779800592956Low risk02026-05-26
3.7.0-SNAPSHOT.1779474358620Low risk02026-05-25
3.7.0-SNAPSHOT.1779717706531Low risk02026-05-25

Block this in CI

PkgRadar gates @jahia/jcontent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @jahia/[email protected]