PkgRadar

npm · registry.npmjs.org

@oicl/openbridge-webcomponents-ng

Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 2 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape

Why PkgRadar flagged 2.0.0-next.66

SeveritySignalEvidence
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 2 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.0-next.66Review42026-06-12
2.0.0-next.65Review42026-06-12
2.0.0-next.64Review42026-06-12
2.0.0-next.63Review42026-06-12
2.0.0-next.62Review42026-06-11
2.0.0-next.61Review42026-06-11
2.0.0-next.60Review42026-06-10
1.0.1Low risk02026-06-10
2.0.0-next.59Review42026-06-10
2.0.0-next.58Review42026-06-09
2.0.0-next.57Review42026-06-08
2.0.0-next.56Review42026-06-05
2.0.0-next.55Review42026-06-05
2.0.0-next.54Review42026-06-04
2.0.0-next.53Review42026-06-04
2.0.0-next.52Review42026-06-03
2.0.0-next.51Review42026-06-02
2.0.0-next.50Review42026-06-02
2.0.0-next.49Review42026-06-01
2.0.0-next.48Low risk02026-05-29
2.0.0-next.47Low risk02026-05-29
2.0.0-next.45Low risk02026-05-28
2.0.0-next.43Low risk02026-05-27
2.0.0-next.42Low risk02026-05-26
2.0.0-next.41Low risk02026-05-26
2.0.0-next.39Low risk02026-05-24
2.0.0-next.40Low risk02026-05-24

Block this in CI

PkgRadar gates @oicl/openbridge-webcomponents-ng (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @oicl/[email protected]