PkgRadar

npm · registry.npmjs.org

ros2-web2d

Remote Dependency Spec: devDependencies.grunt-execute="git+https://github.com/gruntjs-updater/grunt-execute.git#peerDep"

Why PkgRadar flagged 1.9.0

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.grunt-execute="git+https://github.com/gruntjs-updater/grunt-execute.git#peerDep" · package.json
mediumRemote Dependency SpecdevDependencies.grunt-pipe="git+https://github.com/RobotWebTools/grunt-pipe.git" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.9.0Review162026-06-06
1.7.3Review162026-06-02
1.8.1Review162026-06-02

Block this in CI

PkgRadar gates ros2-web2d (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]