PkgRadar

npm · registry.npmjs.org

tg-map-core

Remote Dependency Spec: dependencies.coordtransform="github:TranscodeGroup/coordtransform#fa1d037ed54bac0beddfd62d2c4c00f882b07004"

Why PkgRadar flagged 4.2.11

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.coordtransform="github:TranscodeGroup/coordtransform#fa1d037ed54bac0beddfd62d2c4c00f882b07004" · package.json
mediumRemote Dependency SpecdevDependencies.@types/bmapgl-browser="github:TranscodeGroup/DefinitelyTyped#path:/types/bmapgl-browser&9ed2593293c552e55d3defc8ca17d13d5f37cf5b" · package.json
mediumRemote Dependency SpecdevDependencies.bmaplib.heatmap="github:TranscodeGroup/BMapLib.Heatmap#v2" · package.json
mediumRemote Dependency SpecdevDependencies.bmaplib.markerclusterer="github:TranscodeGroup/BMapLib.MarkerClusterer#e24e502c4e626a8e698ae3fcb17d0b3c31815f0f" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
4.2.11Review252026-06-11
4.2.10Review252026-06-10
4.2.9Review252026-06-03
4.2.7Review252026-06-01
4.2.8Review252026-06-01

Block this in CI

PkgRadar gates tg-map-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]