npm · registry.npmjs.org
@nypl/dgx-header-component
Remote Dependency Spec: dependencies.dgx-feature-flags="git+https://[email protected]/NYPL/dgx-feature-flags.git#master"
Why PkgRadar flagged 2.7.1-r16
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Dependency Spec | dependencies.dgx-feature-flags="git+https://[email protected]/NYPL/dgx-feature-flags.git#master" · package.json |
| medium | Remote Dependency Spec | dependencies.dgx-react-ga="git+https://[email protected]/NYPL/dgx-react-ga.git#master" · package.json |
| medium | Remote Dependency Spec | dependencies.dgx-skip-navigation-link="git+https://[email protected]/NYPL/dgx-skip-navigation-link.git#master" · package.json |
| medium | Dependency Changed To Remote Vs Previous | dependencies.dgx-feature-flags changed to remote spec in 2.7.1-r16 vs 2.7.0: "git+https://[email protected]/NYPL/dgx-feature-flags.git#master" · package.json |
| medium | Dependency Changed To Remote Vs Previous | dependencies.dgx-react-ga changed to remote spec in 2.7.1-r16 vs 2.7.0: "git+https://[email protected]/NYPL/dgx-react-ga.git#master" · package.json |
| medium | Dependency Changed To Remote Vs Previous | dependencies.dgx-skip-navigation-link changed to remote spec in 2.7.1-r16 vs 2.7.0: "git+https://[email protected]/NYPL/dgx-skip-navigation-link.git#master" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.7.1-r16 | Review | 72 | 2026-06-03 |
2.8.0 | Review | 18 | 2026-05-29 |
Block this in CI
pkgradar gate --ecosystem npm @nypl/[email protected]