PkgRadar

npm · registry.npmjs.org

@trustify-da/trustify-da-javascript-client

Remote Dependency Spec: dependencies.tree-sitter-gomod="github:strum355/tree-sitter-go-mod#56326f2ad478892ace58ff247a97d492a3cbcdda"

Why PkgRadar flagged 0.3.0-ea.9a6adf7

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.tree-sitter-gomod="github:strum355/tree-sitter-go-mod#56326f2ad478892ace58ff247a97d492a3cbcdda" · package.json
mediumRemote Dependency Specdependencies.tree-sitter-requirements="github:Strum355/tree-sitter-requirements#d0261ee76b84253997fe70d7d397e78c006c3801" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0-ea.9a6adf7Review72026-06-11
0.3.0-ea.ec6824bReview72026-06-10
0.3.0Low risk02026-06-10
0.3.0-ea.b68592eReview482026-06-08
0.3.0-ea.41d542eReview482026-06-07
0.3.0-ea.5cc5120Review72026-06-03
0.3.0-ea.d2edf6eReview482026-06-03
0.3.0-ea.6645ba5Review362026-06-03
0.3.0-ea.00f52e4Review362026-06-03
0.3.0-ea.e660b02Review72026-06-02
0.3.0-ea.d8ec262Review72026-05-28
0.3.0-ea.f1e4e15Review72026-05-28

Block this in CI

PkgRadar gates @trustify-da/trustify-da-javascript-client (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @trustify-da/[email protected]
@trustify-da/trustify-da-javascript-client — npm security scan | PkgRadar