PkgRadar

npm · registry.npmjs.org

remsg

Remote Dependency Spec: devDependencies.@changesets/changelog-github="https://pkg.pr.new/changesets/changesets/@changesets/changelog-github@bd27256"

Why PkgRadar flagged 2.0.0

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.@changesets/changelog-github="https://pkg.pr.new/changesets/changesets/@changesets/changelog-github@bd27256" · package.json
mediumRemote Dependency SpecdevDependencies.@changesets/cli="https://pkg.pr.new/changesets/changesets/@changesets/cli@bd27256" · package.json
mediumDependency Changed To Remote Vs PreviousdevDependencies.@changesets/changelog-github changed to remote spec in 2.0.0 vs 1.2.1: "https://pkg.pr.new/changesets/changesets/@changesets/changelog-github@bd27256" · package.json
mediumDependency Changed To Remote Vs PreviousdevDependencies.@changesets/cli changed to remote spec in 2.0.0 vs 1.2.1: "https://pkg.pr.new/changesets/changesets/@changesets/cli@bd27256" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.0High risk1642026-06-03
2.0.1Review442026-05-27

Related campaigns

Block this in CI

PkgRadar gates remsg (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]