PkgRadar

npm · registry.npmjs.org

ncplayer

Remote Dependency Spec: devDependencies.git-hook-tasks="git+https://github.com/ncpa0cpl/git-hook-tasks#4215793"

Why PkgRadar flagged 0.3.1

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.git-hook-tasks="git+https://github.com/ncpa0cpl/git-hook-tasks#4215793" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.1Review22026-05-30
0.2.8Review532026-05-24
0.3.0Review532026-05-24

Block this in CI

PkgRadar gates ncplayer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]