PkgRadar

npm · registry.npmjs.org

pi-session-graph

Remote Dependency Spec: dependencies.agent-session-store="github:ProbabilityEngineer/agent-session-store#v0.1.8"

Why PkgRadar flagged 0.1.9

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.1.9 vs 0.1.8: "node scripts/check-agent-session-store.mjs" · package.json
mediumRemote Dependency Specdependencies.agent-session-store="github:ProbabilityEngineer/agent-session-store#v0.1.8" · package.json
mediumDependency Changed To Remote Vs Previousdependencies.agent-session-store changed to remote spec in 0.1.9 vs 0.1.8: "github:ProbabilityEngineer/agent-session-store#v0.1.8" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.9High risk692026-06-05
0.1.8Review242026-06-05
0.1.6Low risk02026-06-02
0.1.7Low risk02026-06-02
0.1.4Low risk02026-06-02
0.1.1Low risk02026-06-02

Block this in CI

PkgRadar gates pi-session-graph (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]