PkgRadar

npm · registry.npmjs.org

@openhistoricalmap/id

Remote Dependency Spec: devDependencies.@actions/github-script="github:actions/github-script#v8.0.0"

Why PkgRadar flagged 2.29.5

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.@actions/github-script="github:actions/github-script#v8.0.0" · package.json
mediumRemote Dependency SpecdevDependencies.editor-layer-index="github:osmlab/editor-layer-index#gh-pages" · package.json
mediumRemote Dependency SpecdevDependencies.ohm-editor-layer-index="github:openhistoricalmap/ohm-editor-layer-index#dist" · package.json
mediumNew Remote Dependency Vs PreviousdevDependencies.@actions/github-script added in 2.29.5 vs 2.29.3: "github:actions/github-script#v8.0.0" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.29.5Review322026-06-03
2.39.5-ohm.2Review242026-05-29

Block this in CI

PkgRadar gates @openhistoricalmap/id (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @openhistoricalmap/[email protected]