PkgRadar

npm · registry.npmjs.org

echarts-for-react

Remote Dependency Spec: optionalDependencies.@antv/setup="github:antvis/G2#7cb42f57561c321ecb09b4552802ae0ac55b3a7a"

Why PkgRadar flagged 3.0.7

SeveritySignalEvidence
highRemote Dependency SpecoptionalDependencies.@antv/setup="github:antvis/G2#7cb42f57561c321ecb09b4552802ae0ac55b3a7a" · package.json
highNew Remote Dependency Vs PreviousoptionalDependencies.@antv/setup added in 3.0.7 vs 3.0.6: "github:antvis/G2#7cb42f57561c321ecb09b4552802ae0ac55b3a7a" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.7High risk702026-06-03

Related campaigns

Block this in CI

PkgRadar gates echarts-for-react (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]