PkgRadar

npm · registry.npmjs.org

@zkp2p/reclaim-witness-sdk

Remote Dependency Spec: dependencies.@reclaimprotocol/tls="github:reclaimprotocol/tls"

Why PkgRadar flagged 4.0.5-reclaim

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.@reclaimprotocol/tls="github:reclaimprotocol/tls" · package.json
mediumRemote Dependency SpecdevDependencies.@adiwajshing/eslint-config="github:adiwajshing/eslint-config" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
4.0.5-reclaimReview142026-06-05
4.0.6-reclaimReview142026-06-05

Block this in CI

PkgRadar gates @zkp2p/reclaim-witness-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @zkp2p/[email protected]