PkgRadar

npm · registry.npmjs.org

@johnshopkins/ravejs

Remote Dependency Spec: devDependencies.@johnshopkins/jhu-wds="github:johnshopkins/jhu-wds#announcement-banner-fix"

Why PkgRadar flagged 1.0.1

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.@johnshopkins/jhu-wds="github:johnshopkins/jhu-wds#announcement-banner-fix" · package.json
mediumDependency Changed To Remote Vs PreviousdevDependencies.@johnshopkins/jhu-wds changed to remote spec in 1.0.1 vs 1.0.0: "github:johnshopkins/jhu-wds#announcement-banner-fix" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.1Review162026-06-03
1.0.2Review162026-06-03

Block this in CI

PkgRadar gates @johnshopkins/ravejs (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @johnshopkins/[email protected]