PkgRadar

npm · registry.npmjs.org

@roomle/web-sdk

Remote Dependency Spec: optionalDependencies.gl="github:roomle-dev/headless-gl#int/nvidia"

Why PkgRadar flagged 3.8.0-alpha.1

SeveritySignalEvidence
highRemote Dependency SpecoptionalDependencies.gl="github:roomle-dev/headless-gl#int/nvidia" · package.json
highDependency Changed To Remote Vs PreviousoptionalDependencies.gl changed to remote spec in 3.8.0-alpha.1 vs 3.7.0: "github:roomle-dev/headless-gl#int/nvidia" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
3.8.0-alpha.1High risk702026-06-20
3.8.0Review102026-06-18
3.9.0-alpha.1Review102026-06-18
3.9.0-alpha.2Review102026-06-18

Block this in CI

PkgRadar gates @roomle/web-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @roomle/[email protected]