PkgRadar

npm · registry.npmjs.org

@stdlib/stdlib

Remote Dependency Spec: devDependencies.gh-pages="git+https://github.com/Planeshifter/gh-pages.git#main"

Why PkgRadar flagged 0.4.0

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.4.0 vs 0.3.2: "tools/scripts/apply_patches" · package.json
mediumRemote Dependency SpecdevDependencies.gh-pages="git+https://github.com/Planeshifter/gh-pages.git#main" · package.json
mediumRemote Dependency SpecdevDependencies.tap-min="git+https://github.com/Planeshifter/tap-min.git" · package.json
mediumRemote Dependency SpecdevDependencies.tape="git+https://github.com/kgryte/tape.git#fix/globby" · package.json
mediumRemote Dependency SpecdevDependencies.typedoc="git+https://github.com/kgryte/typedoc.git#0.16.11-patch" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.1Review112026-06-06
0.3.2Review92026-06-06
0.4.0High risk772026-06-06

Block this in CI

PkgRadar gates @stdlib/stdlib (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @stdlib/[email protected]
@stdlib/stdlib — npm security scan | PkgRadar