PkgRadar

npm · registry.npmjs.org

@vino.tian/vibe-kanban

Remote Payload: matched "github.com/${repository}/releases/download"

Why PkgRadar flagged 0.1.4419

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/${repository}/releases/download" · package/bin/cli.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.9-t1025Low risk02026-06-09
2026.6.8-t1817Low risk02026-06-08
0.1.4426Low risk02026-06-01
0.1.4425Low risk02026-05-31
0.1.4424Low risk02026-05-30
0.1.4423Low risk02026-05-29
0.1.4422Low risk02026-05-28
0.1.4421Low risk02026-05-27
0.1.4418Low risk02026-05-27
0.1.4420Low risk02026-05-27
0.1.4419Review122026-05-25
0.1.4416Review122026-05-24
0.1.4417Review122026-05-24

Block this in CI

PkgRadar gates @vino.tian/vibe-kanban (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @vino.tian/[email protected]