PkgRadar

npm · registry.npmjs.org

@outputai/output

Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 6 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape

Why PkgRadar flagged 0.7.1-next.bd6bd49.0

SeveritySignalEvidence
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 6 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.1-next.bd6bd49.0Review102026-06-12
0.7.1-next.d67ad85.0Review102026-06-12
0.7.1-next.306c136.0Review152026-06-12
0.7.1-next.5a29fff.0Review152026-06-12
0.7.1-next.2a4105c.0Review102026-06-11
0.7.1-next.ae5bab4.0Review102026-06-11
0.7.0Review152026-06-10
0.7.1-next.be9352c.0Review152026-06-10
0.6.1-next.f8d698e.0Review152026-06-10
0.6.1-next.7359fe9.0Review152026-06-10
0.6.1-next.f67f4b9.0Review152026-06-09
0.6.1-next.83742db.0Review152026-06-09
0.6.1-next.65cd087.0Review102026-06-09
0.6.1-next.fc6a93e.0Review152026-06-08
0.6.1-next.0d08ff5.0Review152026-06-08
0.6.1-next.2cc4685.0Review102026-06-05
0.6.1-next.5d7e612.0Review152026-06-04
0.6.1-dev.aab2335.0Review102026-06-04
0.6.1-dev.daae905.0Review102026-06-04
0.6.1-next.d3c9b1f.0Review102026-06-03
0.6.1-next.1f47248.0Review102026-06-03
0.6.1-next.383b24b.0Review102026-06-02
0.6.1-next.34badf9.0Review102026-06-02
0.6.0Low risk02026-05-29
0.6.1-next.5a87ebc.0Low risk02026-05-29
0.5.3-next.69060d7.0Low risk02026-05-29
0.5.2Low risk02026-05-28
0.5.3-next.0eeffec.0Low risk02026-05-28
0.5.2-next.93dd22e.0Low risk02026-05-26
0.5.2-next.746400f.0Low risk02026-05-25
0.5.2-next.8738f60.0Low risk02026-05-25

Block this in CI

PkgRadar gates @outputai/output (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @outputai/[email protected]