PkgRadar

npm · registry.npmjs.org

react-native-gesture-handler

Remote Dependency Spec: dependencies.hammerjs="https://github.com/naver/hammer.js.git"

Why PkgRadar flagged 1.5.6

SeveritySignalEvidence
highRemote Dependency Specdependencies.hammerjs="https://github.com/naver/hammer.js.git" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
3.1.0-nightly-20260610-96dfc0099Low risk02026-06-10
1.6.0Low risk02026-06-10
3.0.1Low risk02026-06-10
1.5.6Review32026-06-10
1.5.5Review32026-06-10
3.1.0-nightly-20260609-6ba9d63d4Low risk02026-06-09
3.1.0-nightly-20260608-9a9f8b41eLow risk02026-06-08
3.1.0-nightly-20260604-183f348f8Low risk02026-06-04
3.1.0-nightly-20260603-45e6ac8a0Low risk02026-06-03
3.1.0-nightly-20260601-4f4f63e1aLow risk02026-06-02
3.1.0-nightly-20260528-548f2c8c3Low risk02026-05-29
3.0.0Low risk02026-05-28
3.0.0-nightly-20260527-5a9551ab7Low risk02026-05-28
3.0.0-nightly-20260526-117087e3dLow risk02026-05-27
3.0.0-nightly-20260522-46a2bde7fLow risk02026-05-27

Block this in CI

PkgRadar gates react-native-gesture-handler (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]