PkgRadar

npm · registry.npmjs.org

@sphereon/ssi-sdk.credential-vcdm-jsonld-provider

Remote Dependency Spec: dependencies.@veramo-community/lds-ecdsa-secp256k1-recovery2020="github:uport-project/EcdsaSecp256k1RecoverySignature2020"

Why PkgRadar flagged 0.40.0

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.@veramo-community/lds-ecdsa-secp256k1-recovery2020="github:uport-project/EcdsaSecp256k1RecoverySignature2020" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.40.0Review62026-06-05
0.39.0Review62026-06-05
0.38.1-next.3Review62026-06-05
0.37.2-next.46Review62026-06-04
0.38.0Review62026-06-04
0.37.2-next.34Review62026-06-04
0.37.2-feature.oid4vc.1.0.45Review62026-06-04

Block this in CI

PkgRadar gates @sphereon/ssi-sdk.credential-vcdm-jsonld-provider (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @sphereon/[email protected]