PkgRadar

npm · registry.npmjs.org

shaka-player

Remote Dependency Spec: devDependencies.eslint-config-google="github:google/eslint-config-google#3ae571a"

Why PkgRadar flagged 5.0.19

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.eslint-config-google="github:google/eslint-config-google#3ae571a" · package.json
mediumRemote Dependency SpecdevDependencies.google-closure-library="github:joeyparrish/closure-library#74db0395" · package.json
mediumRemote Dependency SpecdevDependencies.jsdoc="github:joeyparrish/jsdoc#a1e61a4e" · package.json
mediumRemote Dependency SpecdevDependencies.karma="github:joeyparrish/karma#shaka-fixes" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
5.0.19Review92026-06-08
4.16.35Review92026-06-08
4.15.47Review92026-06-08
4.16.34Review92026-06-08
5.0.18Review92026-06-01
5.1.7Review92026-06-01
5.0.17Review322026-05-25
5.1.6Review422026-05-25

Block this in CI

PkgRadar gates shaka-player (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]