PkgRadar

npm · registry.npmjs.org

@patternslib/patternslib

Remote Dependency Spec: dependencies.slick-carousel="git+https://github.com/kenwheeler/slick.git#d0716f19aa730006ee80ab026625fb1107816a97"

Why PkgRadar flagged 9.10.5

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.slick-carousel="git+https://github.com/kenwheeler/slick.git#d0716f19aa730006ee80ab026625fb1107816a97" · package.json
mediumRemote Dependency Specdependencies.slides="git+https://github.com/Patternslib/slides.git" · package.json
mediumDependency Changed To Remote Vs Previousdependencies.slick-carousel changed to remote spec in 9.10.5 vs 9.10.5-alpha.0: "git+https://github.com/kenwheeler/slick.git#d0716f19aa730006ee80ab026625fb1107816a97" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
9.10.5Review362026-06-05
9.10.6Review72026-06-05

Block this in CI

PkgRadar gates @patternslib/patternslib (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @patternslib/[email protected]
@patternslib/patternslib — npm security scan | PkgRadar