PkgRadar

npm · registry.npmjs.org

@mkuznets/hello-world

Remote Dependency Spec: devDependencies.license-tool="https://github.com/che-incubator/dash-licenses.git#c09f697ea6336ce82d365654dfeb7ef6e9c84768"

Why PkgRadar flagged 7.119.0

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.license-tool="https://github.com/che-incubator/dash-licenses.git#c09f697ea6336ce82d365654dfeb7ef6e9c84768" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
7.119.0-next-8509c17Low risk02026-06-11
7.119.0Review22026-06-10
7.117.0-next-0a0ac74Low risk02026-06-10
1.0.0Low risk02026-06-10
7.118.0-next-f2777fcReview162026-06-10
7.117.0-next-666f4daLow risk02026-06-10
7.117.0-next-08b88f2Low risk02026-06-10

Block this in CI

PkgRadar gates @mkuznets/hello-world (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @mkuznets/[email protected]