PkgRadar

npm · registry.npmjs.org

first-tree

Credential file access: matched "GITHUB_TOKEN"

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.3Review42026-05-28
0.5.2Review42026-05-26
0.5.2-alpha.21.1Review152026-05-25
0.5.2-alpha.20.1Review152026-05-25
0.5.2-alpha.19.1Review52026-05-25
0.5.2-alpha.18.1Review52026-05-25
0.5.2-alpha.17.1Review52026-05-25
0.5.2-alpha.16.1Review52026-05-25
0.5.2-alpha.15.1Review272026-05-25
0.5.2-alpha.14.1Review272026-05-25
0.5.2-alpha.13.1Review272026-05-25
0.5.2-alpha.12.1Review622026-05-25
0.5.2-alpha.10.1Review622026-05-25
0.5.2-alpha.11.1Review622026-05-25

Block this in CI

PkgRadar gates first-tree (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]