PkgRadar

npm · registry.npmjs.org

querysub

Remote Dependency Spec: dependencies.js-sha256="https://github.com/sliftist/js-sha256"

Why PkgRadar flagged 0.475.0

SeveritySignalEvidence
highRemote Dependency Specdependencies.js-sha256="https://github.com/sliftist/js-sha256" · package.json
highRemote Dependency Specdependencies.node-forge="https://github.com/sliftist/forge#e618181b469b07bdc70b968b0391beb8ef5fecd6" · package.json
mediumCredential file accessmatched ".ssh/" · package/src/4-deploy/git.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.475.0High risk192026-06-17
0.474.0High risk192026-06-16
0.473.0High risk192026-06-10
0.472.0High risk192026-06-10
0.471.0High risk192026-06-10
0.470.0High risk192026-06-10
0.468.0High risk192026-06-10
0.469.0High risk192026-06-10
0.467.0High risk192026-06-10
0.462.0Review192026-05-30
0.461.0Review192026-05-30
0.460.0Review192026-05-30
0.459.0Review192026-05-30
0.458.0Review192026-05-30
0.456.0Review192026-05-30
0.457.0Review192026-05-30
0.454.0Review192026-05-30
0.455.0Review192026-05-30
0.466.0Review192026-05-30
0.464.0Review192026-05-29
0.465.0Review192026-05-29

Block this in CI

PkgRadar gates querysub (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]