PkgRadar

npm · registry.npmjs.org

size-sensor

Remote Dependency Spec: optionalDependencies.@antv/setup="github:antvis/G2#7cb42f57561c321ecb09b4552802ae0ac55b3a7a"

Why PkgRadar flagged 1.0.4

SeveritySignalEvidence
highRemote Dependency SpecoptionalDependencies.@antv/setup="github:antvis/G2#7cb42f57561c321ecb09b4552802ae0ac55b3a7a" · package.json
highNew Remote Dependency Vs PreviousoptionalDependencies.@antv/setup added in 1.0.4 vs 1.0.3: "github:antvis/G2#7cb42f57561c321ecb09b4552802ae0ac55b3a7a" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.4High risk702026-06-03

Related campaigns

Block this in CI

PkgRadar gates size-sensor (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]