PkgRadar

npm · registry.npmjs.org

oojs-ui

Remote Dependency Spec: devDependencies.grunt-promise-q="git+https://github.com/jdforrester/grunt-promise-q.git#v0.1.1-wmf.1"

Why PkgRadar flagged 0.53.0

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.grunt-promise-q="git+https://github.com/jdforrester/grunt-promise-q.git#v0.1.1-wmf.1" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.53.0Review22026-06-11
0.53.1Review22026-06-11
0.53.2Review22026-06-11
0.54.0Review22026-06-11

Block this in CI

PkgRadar gates oojs-ui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]