PkgRadar

npm · registry.npmjs.org

clay-generator

Remote Dependency Spec: dependencies.handlebars-group-by="https://github.com/jonasalfthan/handlebars-group-by"

Why PkgRadar flagged 0.2.7

SeveritySignalEvidence
highRemote Dependency Specdependencies.handlebars-group-by="https://github.com/jonasalfthan/handlebars-group-by" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.7High risk82026-06-10
0.2.8High risk82026-06-10
0.2.9High risk82026-06-10
0.3.0High risk82026-06-10

Block this in CI

PkgRadar gates clay-generator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]