PkgRadar

npm · registry.npmjs.org

dashmate

Remote Dependency Spec: dependencies.enquirer="github:dashpay/enquirer#patch-1"

Why PkgRadar flagged 4.0.0-beta.2

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.enquirer="github:dashpay/enquirer#patch-1" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
4.0.0-beta.2Review32026-06-02
4.0.0-beta.1Review32026-06-02
3.1.0-dev.8Review72026-05-29
3.1.0-dev.7Review72026-05-28
3.1.0-dev.5Review72026-05-27
3.1.0-dev.6Review72026-05-27

Block this in CI

PkgRadar gates dashmate (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]