PkgRadar

npm · registry.npmjs.org

@s-tier-building-automation/stier-mcp-server

Remote Dependency Spec: dependencies.obix-js="github:Rise-Building-Technology/obix-js"

Why PkgRadar flagged 2.1.0

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.obix-js="github:Rise-Building-Technology/obix-js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.0High risk172026-06-20
2.1.1High risk172026-06-20
2.2.0High risk172026-06-20
2.4.2High risk292026-06-20

Block this in CI

PkgRadar gates @s-tier-building-automation/stier-mcp-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @s-tier-building-automation/[email protected]