PkgRadar

npm · registry.npmjs.org

igv_feifei

Remote Dependency Spec: devDependencies.circular-view="github:igvteam/circular-view#v0.2.4"

Why PkgRadar flagged 3.0.8-dev1.4.5

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.circular-view="github:igvteam/circular-view#v0.2.4" · package.json
mediumRemote Dependency SpecdevDependencies.hdf5-indexed-reader="github:jrobinso/hdf5-indexed-reader#v0.5.6" · package.json
mediumRemote Dependency SpecdevDependencies.igv-utils="github:igvteam/igv-utils#v1.5.9" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.8-dev1.4.5Review122026-06-11
3.0.8-dev1.4.6Review122026-06-11
3.0.8-dev1.4.7Review122026-06-11
3.0.8-dev1.4.8Review122026-06-11

Block this in CI

PkgRadar gates igv_feifei (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]