PkgRadar

npm · registry.npmjs.org

@loczer/storefront-sdk

Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 16 dependency(ies) (4 with loose/empty version specs) — dependency-confusion / install-chain loader shape

Why PkgRadar flagged 0.148.0

SeveritySignalEvidence
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 16 dependency(ies) (4 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.159.0Low risk02026-06-12
0.158.0Low risk02026-06-12
0.157.0Low risk02026-06-12
0.156.0Low risk02026-06-12
0.154.0Low risk02026-06-12
0.155.0Low risk02026-06-12
0.153.0Low risk02026-06-11
0.152.0Low risk02026-06-11
0.151.0Low risk02026-06-11
0.150.0Low risk02026-06-10
0.149.0Low risk02026-06-10
0.148.0Review42026-06-09
0.147.0Review42026-06-09
0.145.0Review42026-06-09
0.146.0Review42026-06-09
0.144.0Review42026-06-09
0.143.0Review42026-06-09
0.142.0Review42026-06-08
0.141.0Review42026-06-08
0.140.0Review42026-06-02
0.139.0Review42026-06-02
0.138.0Review42026-06-01
0.137.0Review42026-06-01
0.136.0Review42026-05-31
0.135.0Review42026-05-31
0.134.0Low risk02026-05-30
0.133.0Low risk02026-05-28
0.132.0Low risk02026-05-28
0.131.0Low risk02026-05-27
0.130.0Low risk02026-05-26
0.129.0Low risk02026-05-24
0.128.0Low risk02026-05-24
0.126.0Low risk02026-05-24
0.127.0Low risk02026-05-24

Block this in CI

PkgRadar gates @loczer/storefront-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @loczer/[email protected]