PkgRadar

npm · registry.npmjs.org

@openzeppelin/hardhat-upgrades

Remote Dependency Spec: devDependencies.forge-std="github:foundry-rs/forge-std#v1.16.1"

Why PkgRadar flagged 4.0.2

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.forge-std="github:foundry-rs/forge-std#v1.16.1" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
4.0.2Review22026-06-10
4.0.1Review162026-06-03
4.0.0-alpha.0Review162026-06-03
4.0.0Review22026-06-01

Block this in CI

PkgRadar gates @openzeppelin/hardhat-upgrades (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @openzeppelin/[email protected]