PkgRadar

npm · registry.npmjs.org

@vtex/faststore-plugin-buyer-portal

Remote Dependency Spec: devDependencies.@faststore/core="https://pkg.pr.new/vtex/faststore/@faststore/[email protected]"

Why PkgRadar flagged 1.3.82-experimental.20260528170039

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.@faststore/core="https://pkg.pr.new/vtex/faststore/@faststore/[email protected]" · package.json
mediumRemote Dependency SpecdevDependencies.@faststore/ui="https://pkg.pr.new/vtex/faststore/@faststore/[email protected]" · package.json
mediumDependency Changed To Remote Vs PreviousdevDependencies.@faststore/core changed to remote spec in 1.3.82-experimental.20260528170039 vs 1.3.82-experimental.20260526193431: "https://pkg.pr.new/vtex/faststore/@faststore/[email protected]" · package.json
mediumDependency Changed To Remote Vs PreviousdevDependencies.@faststore/ui changed to remote spec in 1.3.82-experimental.20260528170039 vs 1.3.82-experimental.20260526193431: "https://pkg.pr.new/vtex/faststore/@faststore/[email protected]" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.82-experimental.20260528170039High risk1042026-06-10
1.3.82-experimental.20260526193431High risk1052026-06-10
2.0.3Low risk02026-06-04
2.0.2Low risk02026-06-03
2.0.1-experimental.20260603001819Low risk02026-06-03
2.0.1-experimental.20260602224223Low risk02026-06-02
2.0.1-experimental.20260602220948Low risk02026-06-02
2.0.0Low risk02026-06-02
2.0.1Low risk02026-06-02
1.3.83-experimental.20260529182803Low risk02026-05-29
1.3.87Low risk02026-05-27

Block this in CI

PkgRadar gates @vtex/faststore-plugin-buyer-portal (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @vtex/[email protected]