PkgRadar

npm · registry.npmjs.org

@stoked-ui/github

Remote Payload: matched "api.github.com/graphql"

Why PkgRadar flagged 0.1.0-alpha.31.1

SeveritySignalEvidence
mediumRemote Payloadmatched "api.github.com/graphql" · package/apiHandlers/getGithubContributions.js
mediumRemote Payloadmatched "api.github.com/graphql" · package/modern/apiHandlers/getGithubContributions.js
mediumRemote Payloadmatched "api.github.com/graphql" · package/node/apiHandlers/getGithubContributions.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.0-alpha.31.1Review102026-06-12
0.0.0-a.0Low risk02026-06-12
0.1.0-alpha.11.2Review362026-06-12
0.1.0-alpha.11.3Review362026-06-12
0.1.0-alpha.13.1Review102026-06-12
0.1.0-alpha.30.1Review102026-06-12

Block this in CI

PkgRadar gates @stoked-ui/github (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @stoked-ui/[email protected]