PkgRadar

npm · registry.npmjs.org

@openfeed/sdk-js

Remote Dependency Spec: devDependencies.proto="git+ssh://[email protected]/openfeed-org/proto.git#master"

Why PkgRadar flagged 1.7.2

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.proto="git+ssh://[email protected]/openfeed-org/proto.git#master" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.7.2Review22026-06-17
1.6.10Review42026-06-17
1.6.11Review42026-06-17
1.6.9Review42026-06-17
1.7.1Review22026-06-17

Block this in CI

PkgRadar gates @openfeed/sdk-js (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @openfeed/[email protected]