PkgRadar

npm · registry.npmjs.org

@kortexya/nodus

Remote Dependency Spec: optionalDependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz"

Why PkgRadar flagged 0.1.7

SeveritySignalEvidence
highRemote Dependency SpecoptionalDependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.7High risk352026-06-16
0.1.6High risk352026-06-16
0.1.5High risk452026-06-14
0.1.4High risk452026-06-14
0.1.3High risk452026-06-14
0.1.2High risk452026-06-14
0.1.1High risk452026-06-14
0.1.0High risk452026-06-14

Block this in CI

PkgRadar gates @kortexya/nodus (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @kortexya/[email protected]