PkgRadar

npm · registry.npmjs.org

@tres-finance/portfolio-plugins

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.16.7-alpha.1

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/plugins/sanctum/lstsPricingJob.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.16.7-alpha.1Review122026-05-26

Block this in CI

PkgRadar gates @tres-finance/portfolio-plugins (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @tres-finance/[email protected]