PkgRadar

npm · registry.npmjs.org

brsh

Remote Dependency Spec: dependencies.ansi_up="git+https://github.com/eliotstocker/ansi_up.git"

Why PkgRadar flagged 2.5.5

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.ansi_up="git+https://github.com/eliotstocker/ansi_up.git" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.5.5Review42026-05-25
2.5.4Review42026-05-25
2.5.3Review42026-05-25
2.5.2Review42026-05-25
2.5.0Review42026-05-25
2.5.1Review42026-05-25
2.4.0Review662026-05-24
2.4.1Review662026-05-24

Block this in CI

PkgRadar gates brsh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]