PkgRadar

npm · registry.npmjs.org

@openlist-frontend/openlist-frontend

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 4.2.2

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/assets/About-B8Z3nTEE.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/lite/assets/About-BJhlrkSM.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/assets/About-legacy-BEpxuXvI.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/lite/assets/About-legacy-D9AdJZUt.js
mediumRemote Dependency Specdependencies.@hope-ui/solid="github:OpenListTeam/hope-ui#31b436e36ae5d266016814ba71a442ffa9d91181" · package.json
mediumRemote Dependency Specdependencies.mpegts.js="github:OpenListTeam/mpegts.js#1e51e0f6f918cf08e05dfae9c7bfcf658d6b4ac2" · package.json
mediumDependency Changed To Remote Vs Previousdependencies.@hope-ui/solid changed to remote spec in 4.2.2 vs 4.2.1: "github:OpenListTeam/hope-ui#31b436e36ae5d266016814ba71a442ffa9d91181" · package.json
mediumDependency Changed To Remote Vs Previousdependencies.mpegts.js changed to remote spec in 4.2.2 vs 4.2.1: "github:OpenListTeam/mpegts.js#1e51e0f6f918cf08e05dfae9c7bfcf658d6b4ac2" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
4.2.2High risk962026-06-10
4.2.1Review432026-05-25

Block this in CI

PkgRadar gates @openlist-frontend/openlist-frontend (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @openlist-frontend/[email protected]