npm · registry.npmjs.org
@velora-dex/widget
Remote Dependency Spec: dependencies.@velora-dex/sdk="github:VeloraDEX/sdk#chore/order_refund_field"
Why PkgRadar flagged 0.8.5-dev.0
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Dependency Spec | dependencies.@velora-dex/sdk="github:VeloraDEX/sdk#chore/order_refund_field" · package.json |
| medium | Dependency Changed To Remote Vs Previous | dependencies.@velora-dex/sdk changed to remote spec in 0.8.5-dev.0 vs 0.8.4: "github:VeloraDEX/sdk#chore/order_refund_field" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.8.5-dev.0 | Review | 24 | 2026-06-15 |
0.8.4 | Low risk | 0 | 2026-06-02 |
0.8.4-dev.0 | Low risk | 0 | 2026-05-29 |
0.8.3 | Low risk | 0 | 2026-05-28 |
0.8.3-dev.0 | Low risk | 0 | 2026-05-25 |
0.8.3-dev.1 | Low risk | 0 | 2026-05-25 |
Block this in CI
pkgradar gate --ecosystem npm @velora-dex/[email protected]