PkgRadar

npm · registry.npmjs.org

heyio

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 1.13.0

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/copilot/skills.js

Scanned versions

VersionVerdictScoreScanned (UTC)
4.3.3Low risk02026-06-07
4.3.4Low risk02026-06-07
4.3.2Low risk02026-06-07
4.3.1Low risk02026-06-07
4.3.0Low risk02026-06-07
4.2.5Low risk02026-06-06
4.2.7Low risk02026-06-06
4.2.4Low risk02026-06-06
4.2.3Low risk02026-06-06
4.2.2Low risk02026-06-06
4.2.1Low risk02026-06-06
4.2.0Low risk02026-06-06
4.1.4Low risk02026-06-06
4.1.3Low risk02026-06-05
4.1.2Low risk02026-06-05
4.1.0Low risk02026-06-05
4.0.7Low risk02026-06-05
4.0.5Low risk02026-06-05
4.0.6Low risk02026-06-05
4.0.3Low risk02026-06-05
4.0.2Low risk02026-06-05
4.0.1Low risk02026-06-05
4.0.0Low risk02026-06-05
3.4.0Low risk02026-06-04
3.3.5Low risk02026-06-04
3.3.4Low risk02026-06-03
3.3.3Low risk02026-06-03
3.3.2Low risk02026-06-03
3.3.1Low risk02026-06-02
3.3.0Low risk02026-06-02
3.2.3Low risk02026-06-02
3.2.1Low risk02026-06-01
3.2.2Low risk02026-06-01
3.1.12Low risk02026-06-01
3.1.13Low risk02026-06-01
3.1.10Low risk02026-06-01
3.1.9Low risk02026-06-01
3.1.8Low risk02026-06-01
3.1.7Low risk02026-06-01
3.1.6Low risk02026-06-01
3.1.5Low risk02026-06-01
3.1.4Low risk02026-06-01
3.1.3Low risk02026-05-31
3.1.2Low risk02026-05-31
3.1.1Low risk02026-05-31
3.1.0Low risk02026-05-31
3.0.14Low risk02026-05-31
3.0.13Low risk02026-05-31
3.0.12Low risk02026-05-31
3.0.11Low risk02026-05-31
3.0.10Low risk02026-05-31
3.0.9Low risk02026-05-31
3.0.8Low risk02026-05-30
3.0.7Low risk02026-05-30
3.0.6Low risk02026-05-30
3.0.5Low risk02026-05-30
3.0.4Low risk02026-05-30
3.0.3Low risk02026-05-30
3.0.1Low risk02026-05-30
3.0.2Low risk02026-05-30
3.0.0Low risk02026-05-30
1.13.0Review52026-05-30
1.12.1Review52026-05-29
1.11.2Review52026-05-29
1.12.0Review52026-05-29
1.11.0Review52026-05-29
1.10.6Review52026-05-29
1.10.3Review62026-05-29
1.10.4Review62026-05-29
1.5.3Review82026-05-28
1.5.4Review62026-05-28
1.2.3Review12026-05-27
1.2.4Review12026-05-27
0.38.0Review32026-05-26
0.39.0Review32026-05-26
0.37.0Review32026-05-26
0.36.0Review32026-05-25
0.35.0Review32026-05-25
0.34.0Review32026-05-25
0.33.1Review472026-05-25
0.33.0Review472026-05-25
0.32.0Review472026-05-25
0.31.0Review472026-05-24
0.30.1Review472026-05-24
0.29.0Review472026-05-24
0.30.0Review472026-05-24

Block this in CI

PkgRadar gates heyio (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]