PkgRadar

npm · registry.npmjs.org

matterviz

Remote Dependency Spec: devDependencies.@janosh/vite-config="github:janosh/dotfiles"

Why PkgRadar flagged 0.4.0

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.@janosh/vite-config="github:janosh/dotfiles" · package.json
mediumNew Remote Dependency Vs PreviousdevDependencies.@janosh/vite-config added in 0.4.0 vs 0.3.7: "github:janosh/dotfiles" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.0Review162026-06-06
0.3.7Low risk02026-05-30
0.3.5Low risk02026-05-30
0.3.6Low risk02026-05-30

Block this in CI

PkgRadar gates matterviz (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]
matterviz — npm security scan | PkgRadar