PkgRadar

npm · registry.npmjs.org

@lordbex/thelounge

Remote Dependency Spec: dependencies.irc-framework="https://codeload.github.com/kiwiirc/irc-framework/tar.gz/9578e59a1056499e4a03a0f0fd2c260e9aadc541"

Why PkgRadar flagged 4.8.5

SeveritySignalEvidence
highRemote Dependency Specdependencies.irc-framework="https://codeload.github.com/kiwiirc/irc-framework/tar.gz/9578e59a1056499e4a03a0f0fd2c260e9aadc541" · package.json
highDependency Changed To Remote Vs Previousdependencies.irc-framework changed to remote spec in 4.8.5 vs 4.8.1: "https://codeload.github.com/kiwiirc/irc-framework/tar.gz/9578e59a1056499e4a03a0f0fd2c260e9aadc541" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
4.8.1Review242026-06-17
4.8.5High risk242026-06-17
4.8.6Review32026-06-17
4.8.7-preReview32026-06-17

Block this in CI

PkgRadar gates @lordbex/thelounge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @lordbex/[email protected]