PkgRadar

npm · registry.npmjs.org

@trackunit/css-core

Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 4 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape

Why PkgRadar flagged 1.14.29

SeveritySignalEvidence
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 4 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.14.29Review72026-06-16
1.14.29-alpha-0424feab298.0Review72026-06-15
1.14.29-alpha-84ab66282fc.0Review72026-06-15
1.14.28Review72026-06-11
1.14.27Review72026-06-10
1.14.26Review72026-06-10
1.14.25-alpha-27ad777c16e.0Review72026-06-10
1.14.24-alpha-9d327375fc1.0Review72026-06-10
1.14.22Review72026-06-09
1.14.21Review72026-06-08
1.14.20Review72026-06-08
1.14.19Review72026-06-08
1.14.18Review72026-06-08
1.14.17Review72026-06-08
1.14.16Review72026-06-08
1.14.16-alpha-13587994969.0Review72026-06-08
1.14.15-alpha-3c308b4aefc.0Review72026-06-05
1.14.15Review72026-06-05
1.14.15-alpha-ecf53e535f3.0Review72026-06-05
1.14.14Review72026-06-04
1.14.13-alpha-2ff0206584d.0Review72026-06-04
1.14.13Review72026-06-04
1.14.12Review72026-06-02
1.14.11Review72026-06-01
1.14.10Low risk02026-05-28
1.14.9Low risk02026-05-28
1.14.8Low risk02026-05-27
1.14.8-alpha-2189b51c981.0Low risk02026-05-26
1.14.8-alpha-d37885bfce4.0Low risk02026-05-26
1.14.6Low risk02026-05-26
1.14.7Low risk02026-05-26

Block this in CI

PkgRadar gates @trackunit/css-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @trackunit/[email protected]