PkgRadar

npm · registry.npmjs.org

@payfit/unity-icons

Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 3 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape

Why PkgRadar flagged 2.46.17

SeveritySignalEvidence
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 3 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.46.37Low risk02026-06-12
2.46.36Low risk02026-06-12
2.46.35Low risk02026-06-11
2.46.34Low risk02026-06-11
2.46.33Low risk02026-06-11
2.46.32Low risk02026-06-11
2.46.31Low risk02026-06-10
2.46.30Low risk02026-06-10
2.46.29Low risk02026-06-10
2.46.28Low risk02026-06-10
2.46.27Low risk02026-06-10
2.46.26Low risk02026-06-09
2.46.25Low risk02026-06-08
2.46.24Low risk02026-06-08
2.46.23Low risk02026-06-08
2.46.22Low risk02026-06-08
2.46.21Low risk02026-06-08
2.46.20Low risk02026-06-08
2.46.19Low risk02026-06-04
2.46.18Low risk02026-06-04
2.46.17Review72026-06-04
2.46.16Low risk02026-06-04
2.46.15Low risk02026-06-04
2.46.14Low risk02026-06-04
2.46.13Review72026-06-03
2.46.12Low risk02026-06-03
2.46.11Low risk02026-06-03
2.46.10Low risk02026-06-03
2.46.9Low risk02026-06-03
2.46.7Low risk02026-06-02
2.46.8Low risk02026-06-02
2.46.6Low risk02026-06-02
2.46.5Low risk02026-06-02
2.46.4Low risk02026-06-02
2.46.3Low risk02026-06-02
2.46.2Low risk02026-06-01
2.46.1Low risk02026-06-01
2.46.0Low risk02026-06-01
2.45.0Low risk02026-06-01
2.44.1Low risk02026-06-01
2.44.0Low risk02026-06-01
2.43.6Low risk02026-05-29
2.43.4Low risk02026-05-29
2.43.5Low risk02026-05-29
2.43.3Low risk02026-05-29
2.43.1Low risk02026-05-28
2.43.2Low risk02026-05-28
2.43.0Low risk02026-05-27
2.42.7Low risk02026-05-27
2.42.6Low risk02026-05-27
2.42.5Low risk02026-05-26
2.42.4Low risk02026-05-26
2.42.3Low risk02026-05-26
2.42.1Low risk02026-05-25
2.42.2Low risk02026-05-25

Block this in CI

PkgRadar gates @payfit/unity-icons (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @payfit/[email protected]