PkgRadar

npm · registry.npmjs.org

ember-flexberry-gis

Remote Dependency Spec: devDependencies.leaflet-side-by-side="git+https://github.com/asola-bi4group/leaflet-side-by-side.git#fix-multilayer-clip"

Why PkgRadar flagged 0.9.0-beta.1

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.leaflet-side-by-side="git+https://github.com/asola-bi4group/leaflet-side-by-side.git#fix-multilayer-clip" · package.json
mediumRemote Dependency SpecdevDependencies.semantic-ui-ember="git+https://github.com/Flexberry/Semantic-UI-Ember.git#version-0.9.3" · package.json
mediumDependency Changed To Remote Vs PreviousdevDependencies.leaflet-side-by-side changed to remote spec in 0.9.0-beta.1 vs 0.8.0: "git+https://github.com/asola-bi4group/leaflet-side-by-side.git#fix-multilayer-clip" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.0-beta.1Review242026-06-05
0.9.1Review82026-06-05

Block this in CI

PkgRadar gates ember-flexberry-gis (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]