PkgRadar

npm · registry.npmjs.org

@make-software/csprclick-ui

Remote Dependency Spec: dependencies.@make-software/cspr-design="github:make-software/cspr-design#0c4ef00c109704d027a4e92b54816bbb0817c73b"

Why PkgRadar flagged 2.0.5

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.@make-software/cspr-design="github:make-software/cspr-design#0c4ef00c109704d027a4e92b54816bbb0817c73b" · package.json
mediumDependency Changed To Remote Vs Previousdependencies.@make-software/cspr-design changed to remote spec in 2.0.5 vs 2.0.4: "github:make-software/cspr-design#0c4ef00c109704d027a4e92b54816bbb0817c73b" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.5Review242026-06-04
2.1.0Review32026-06-04

Block this in CI

PkgRadar gates @make-software/csprclick-ui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @make-software/[email protected]