PkgRadar

npm · registry.npmjs.org

geonetwork-ui

Remote Dependency Spec: dependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz"

Why PkgRadar flagged 2.10.0-dev.cf0577fae

SeveritySignalEvidence
highRemote Dependency Specdependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.10.0-dev.cf0577faeHigh risk62026-06-12
2.10.0-dev.0d851f690High risk62026-06-11
2.10.0-dev.89f0dfe6fHigh risk62026-06-11
2.10.0-dev.de2fa8e42High risk62026-06-10
2.10.0-dev.7e58935b2High risk62026-06-10
2.10.0-dev.fc6515c0bHigh risk62026-06-10
2.9.0High risk62026-06-10
2.10.0-dev.cc63fa135High risk62026-06-10
2.10.0-dev.0d752aeb4High risk62026-06-10
2.10.0-dev.cbf02ead8High risk62026-06-10
2.10.0-dev.69145ed6aHigh risk62026-06-10
2.10.0-dev.6fa5006ebHigh risk62026-06-10
2.10.0-dev.5f1c6f718High risk62026-06-10
2.10.0-dev.d0cd0940bHigh risk62026-06-10
2.10.0-dev.122ccbde0High risk62026-06-10
2.10.0-dev.91673b3baReview112026-05-28
2.10.0-dev.a9cc01fc7Review112026-05-28

Block this in CI

PkgRadar gates geonetwork-ui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]