PkgRadar

npm · registry.npmjs.org

biblio-react

Remote Dependency Spec: devDependencies.react-draggable="github:WiXSL/react-draggable"

Why PkgRadar flagged 3.0.0-alpha336-popup

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.react-draggable="github:WiXSL/react-draggable" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.0-alpha336-popupReview22026-06-16
3.0.0-alpha335-popupReview22026-06-16
3.0.0-alpha334-popupReview22026-06-08
3.0.0-alpha333-popupReview22026-06-08
3.0.0-alpha332-popupReview22026-06-04
3.0.0-alpha331-popupReview22026-06-04
3.0.0-alpha329-popupReview22026-06-04
3.0.0-alpha330-popupReview22026-06-04
3.0.0-alpha328-popupReview22026-06-03
3.0.0-alpha327-popupReview22026-06-02
3.0.0-alpha326-popupReview22026-06-02
3.0.0-alpha325-popupReview22026-06-01
3.0.0-alpha323-popupReview22026-05-26
3.0.0-alpha324-popupReview22026-05-26

Block this in CI

PkgRadar gates biblio-react (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]