PkgRadar

npm · registry.npmjs.org

binary-collections

Remote Dependency Spec: dependencies.cross-spawn="https://github.com/dimaslanjaka/node-cross-spawn/raw/78b09a1f799430fb251c1b438ec56ce7957674f4/release/cross-spawn.tgz"

Why PkgRadar flagged 2.0.14

SeveritySignalEvidence
highRemote Dependency Specdependencies.cross-spawn="https://github.com/dimaslanjaka/node-cross-spawn/raw/78b09a1f799430fb251c1b438ec56ce7957674f4/release/cross-spawn.tgz" · package.json
highRemote Dependency Specdependencies.git-command-helper="https://github.com/dimaslanjaka/git-command-helper/raw/ed17f70eb7444d24bd8eb984a4afe9fd64652838/release/git-command-helper.tgz" · package.json
highRemote Dependency Specdependencies.sbg-utility="https://github.com/dimaslanjaka/static-blog-generator/raw/44e5c7b79b4e60f8c2d34857c27b8ce677d7493e/packages/sbg-utility/release/sbg-utility.tgz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.14High risk252026-06-03
2.0.13High risk722026-06-03
2.0.12High risk452026-06-03
2.0.11Review352026-05-26

Related campaigns

Block this in CI

PkgRadar gates binary-collections (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]