PkgRadar

npm · registry.npmjs.org

@selfxyz/common

Remote Dependency Spec: dependencies.@anon-aadhaar/core="https://gitpkg.vercel.app/selfxyz/anon-aadhaar/packages/core?1b9efa501cff3cf25dc260b060bf611229e316a4"

Why PkgRadar flagged 0.0.8

SeveritySignalEvidence
highRemote Dependency Specdependencies.@anon-aadhaar/core="https://gitpkg.vercel.app/selfxyz/anon-aadhaar/packages/core?1b9efa501cff3cf25dc260b060bf611229e316a4" · package.json
mediumRemote Dependency Specdependencies.node-forge="github:remicolin/forge#17a11a632dd0e50343b3b8393245a2696f78afbb" · package.json
highNew Remote Dependency Vs Previousdependencies.@anon-aadhaar/core added in 0.0.8 vs 0.0.7: "https://gitpkg.vercel.app/selfxyz/anon-aadhaar/packages/core?1b9efa501cff3cf25dc260b060bf611229e316a4" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.8High risk362026-06-10
0.0.9Review122026-06-02

Block this in CI

PkgRadar gates @selfxyz/common (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @selfxyz/[email protected]