PkgRadar

npm · registry.npmjs.org

@kyonru/feather

Remote Payload: matched "github.com/love2d/love/releases/download"

Why PkgRadar flagged 3.2.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/love2d/love/releases/download" · package/dist/lib/build/vendor.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.2.0Review32026-06-07
3.1.0Review32026-06-02
3.0.0Review32026-05-31
2.0.0Review32026-05-27
1.5.0Review32026-05-26
1.4.2Review32026-05-25
1.4.1Review602026-05-24
1.3.1Review602026-05-24
1.4.0Review602026-05-24

Block this in CI

PkgRadar gates @kyonru/feather (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @kyonru/[email protected]