PkgRadar

npm · registry.npmjs.org

@miradorlabs/nodejs-sdk

Remote Dependency Spec: dependencies.mirador-gateway-ingest="https://storage.googleapis.com/mirador-shd-packages/gateway/ingest/nodejs/mirador-gateway-ingest-1.0.10.tgz"

Why PkgRadar flagged 2.2.0

SeveritySignalEvidence
highRemote Dependency Specdependencies.mirador-gateway-ingest="https://storage.googleapis.com/mirador-shd-packages/gateway/ingest/nodejs/mirador-gateway-ingest-1.0.10.tgz" · package.json
highDependency Changed To Remote Vs Previousdependencies.mirador-gateway-ingest changed to remote spec in 2.2.0 vs 2.1.2: "https://storage.googleapis.com/mirador-shd-packages/gateway/ingest/nodejs/mirador-gateway-ingest-1.0.10.tgz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.2.0High risk242026-06-13
2.3.0High risk242026-06-10
2.1.2Review122026-05-29

Block this in CI

PkgRadar gates @miradorlabs/nodejs-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @miradorlabs/[email protected]