PkgRadar

npm · registry.npmjs.org

signetai

Remote Dependency Spec: optionalDependencies.signetai-darwin-arm64="https://github.com/Signet-AI/signetai/releases/download/v0.140.2/signetai-darwin-arm64-0.140.2.tgz"

Why PkgRadar flagged 0.140.2

SeveritySignalEvidence
highRemote Dependency SpecoptionalDependencies.signetai-darwin-arm64="https://github.com/Signet-AI/signetai/releases/download/v0.140.2/signetai-darwin-arm64-0.140.2.tgz" · package.json
highRemote Dependency SpecoptionalDependencies.signetai-darwin-x64="https://github.com/Signet-AI/signetai/releases/download/v0.140.2/signetai-darwin-x64-0.140.2.tgz" · package.json
highRemote Dependency SpecoptionalDependencies.signetai-linux-arm64="https://github.com/Signet-AI/signetai/releases/download/v0.140.2/signetai-linux-arm64-0.140.2.tgz" · package.json
highRemote Dependency SpecoptionalDependencies.signetai-linux-x64="https://github.com/Signet-AI/signetai/releases/download/v0.140.2/signetai-linux-x64-0.140.2.tgz" · package.json
highRemote Dependency SpecoptionalDependencies.signetai-win32-x64="https://github.com/Signet-AI/signetai/releases/download/v0.140.2/signetai-win32-x64-0.140.2.tgz" · package.json
highDependency Changed To Remote Vs PreviousoptionalDependencies.signetai-darwin-arm64 changed to remote spec in 0.140.2 vs 0.140.1: "https://github.com/Signet-AI/signetai/releases/download/v0.140.2/signetai-darwin-arm64-0.140.2.tgz" · package.json
highDependency Changed To Remote Vs PreviousoptionalDependencies.signetai-darwin-x64 changed to remote spec in 0.140.2 vs 0.140.1: "https://github.com/Signet-AI/signetai/releases/download/v0.140.2/signetai-darwin-x64-0.140.2.tgz" · package.json
highDependency Changed To Remote Vs PreviousoptionalDependencies.signetai-linux-arm64 changed to remote spec in 0.140.2 vs 0.140.1: "https://github.com/Signet-AI/signetai/releases/download/v0.140.2/signetai-linux-arm64-0.140.2.tgz" · package.json
highDependency Changed To Remote Vs PreviousoptionalDependencies.signetai-linux-x64 changed to remote spec in 0.140.2 vs 0.140.1: "https://github.com/Signet-AI/signetai/releases/download/v0.140.2/signetai-linux-x64-0.140.2.tgz" · package.json
highDependency Changed To Remote Vs PreviousoptionalDependencies.signetai-win32-x64 changed to remote spec in 0.140.2 vs 0.140.1: "https://github.com/Signet-AI/signetai/releases/download/v0.140.2/signetai-win32-x64-0.140.2.tgz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.140.2High risk2052026-06-13
0.140.1High risk2052026-06-11
0.139.0High risk2052026-06-11
0.138.34High risk2052026-06-11
0.138.33High risk2052026-06-10
0.138.32High risk2052026-06-10
0.138.31High risk2052026-06-10
0.138.30High risk2052026-06-10
0.138.25High risk2052026-06-10
0.138.26High risk2052026-06-10
0.138.24High risk2052026-06-10
0.138.23High risk2052026-06-10
0.138.22High risk2052026-06-10
0.138.21High risk2052026-06-10
0.138.20High risk2052026-06-10
0.138.19High risk2052026-06-10
0.138.18High risk2052026-06-10
0.137.3Review412026-05-27
0.137.4Review412026-05-27
0.137.1Review412026-05-25
0.137.0Review962026-05-25
0.136.1Review962026-05-25
0.136.0Review962026-05-25
0.135.0Review962026-05-25
0.134.1Review962026-05-25
0.134.0Review962026-05-25
0.133.1Review962026-05-25
0.133.0Review962026-05-25
0.132.0Review962026-05-25
0.131.0Review962026-05-24
0.130.1Review962026-05-24
0.130.0Review962026-05-24
0.129.0Review962026-05-24
0.128.0Review962026-05-24
0.127.0Review662026-05-24
0.126.0Review662026-05-24
0.125.2Review662026-05-24
0.125.1Review662026-05-24
0.125.0Review662026-05-24
0.124.5Review662026-05-24
0.124.4Review662026-05-24
0.124.3Review662026-05-24

Block this in CI

PkgRadar gates signetai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]