npm · registry.npmjs.org
@spiffcommerce/core
Native Addon Gyp Action: binding.gyp runs a script or chains shell during node-gyp build (executes outside package.json lifecycle)
Why PkgRadar flagged 0.7.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Native Addon Gyp Action | binding.gyp runs a script or chains shell during node-gyp build (executes outside package.json lifecycle) · package/node_modules/canvas/binding.gyp |
| medium | Remote Dependency Spec | dependencies.@spiffcommerce/papyrus="git+ssh://[email protected]:spiffdev/papyrus.git#1a8e96b62555d637eb10c14984c198d66e39564d" · package.json |
| medium | Remote Dependency Spec | dependencies.@spiffcommerce/preview="git+ssh://[email protected]:spiffdev/spiff-preview.git#a9ea43a83ef66df56bd6928a8a8686cb19325328" · package.json |
| high | Remote Dependency Spec | dependencies.canvg="https://github.com/spiffdev/canvg.git#03bcd151b12441e88ecb552bb658356f5bbe92c4" · package.json |
| medium | New Remote Dependency Vs Previous | dependencies.@spiffcommerce/papyrus added in 0.7.0 vs 0.6.15: "git+ssh://[email protected]:spiffdev/papyrus.git#1a8e96b62555d637eb10c14984c198d66e39564d" · package.json |
| medium | New Remote Dependency Vs Previous | dependencies.@spiffcommerce/preview added in 0.7.0 vs 0.6.15: "git+ssh://[email protected]:spiffdev/spiff-preview.git#a9ea43a83ef66df56bd6928a8a8686cb19325328" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
42.0.1 | Review | 7 | 2026-06-17 |
35.0.3 | Review | 12 | 2026-06-16 |
0.7.0 | High risk | 95 | 2026-06-16 |
42.0.0 | Review | 7 | 2026-06-16 |
41.2.0 | Review | 7 | 2026-06-09 |
41.1.2-alpha.0 | Review | 7 | 2026-06-09 |
41.1.1 | Review | 7 | 2026-06-09 |
41.1.0 | Review | 7 | 2026-06-03 |
41.0.3-alpha.2 | Review | 7 | 2026-06-01 |
41.0.3-alpha.1 | Review | 7 | 2026-06-01 |
41.0.3-alpha.0 | Review | 7 | 2026-06-01 |
41.0.1 | Review | 10 | 2026-05-28 |
41.0.2 | Review | 10 | 2026-05-28 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem npm @spiffcommerce/[email protected]