PkgRadar

npm · registry.npmjs.org

@miradorlabs/web-sdk

Remote Dependency Spec: dependencies.mirador-gateway-ingest-web="https://storage.googleapis.com/mirador-shd-packages/gateway/ingest/grpc-web/mirador-gateway-ingest-grpc-web-1.0.10.tgz"

Why PkgRadar flagged 2.3.0

SeveritySignalEvidence
highRemote Dependency Specdependencies.mirador-gateway-ingest-web="https://storage.googleapis.com/mirador-shd-packages/gateway/ingest/grpc-web/mirador-gateway-ingest-grpc-web-1.0.10.tgz" · package.json
highDependency Changed To Remote Vs Previousdependencies.mirador-gateway-ingest-web changed to remote spec in 2.3.0 vs 2.2.2: "https://storage.googleapis.com/mirador-shd-packages/gateway/ingest/grpc-web/mirador-gateway-ingest-grpc-web-1.0.10.tgz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.3.0High risk242026-06-13
2.4.0High risk242026-06-10
2.2.2Review122026-05-29

Block this in CI

PkgRadar gates @miradorlabs/web-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @miradorlabs/[email protected]