PkgRadar

npm · registry.npmjs.org

@schibsted/account-sdk-browser

Remote Dependency Spec: devDependencies.docdash="git+https://github.com/torarvid/docdash.git#v0.5.0"

Why PkgRadar flagged 5.2.6

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.docdash="git+https://github.com/torarvid/docdash.git#v0.5.0" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
5.2.6Review22026-06-11
6.0.0-alpha.2Low risk02026-06-11
6.0.0-alpha.1Review22026-05-26
5.2.7Review22026-05-26

Block this in CI

PkgRadar gates @schibsted/account-sdk-browser (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @schibsted/[email protected]