PkgRadar

npm · registry.npmjs.org

@uniformdev/cli

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 20.66.1-alpha.1

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/index.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
20.66.1-alpha.1Review32026-06-03
20.66.1Review32026-06-02
20.66.1-alpha.4Review32026-06-02
20.63.1-alpha.17Review32026-06-01
20.66.0Review32026-05-28
20.62.1-alpha.4Review32026-05-27
20.64.1-alpha.3Review32026-05-26
20.65.0Review32026-05-26

Block this in CI

PkgRadar gates @uniformdev/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @uniformdev/[email protected]
@uniformdev/cli — npm security scan | PkgRadar