PkgRadar

npm · registry.npmjs.org

unicast-mpv

Remote Dependency Spec: dependencies.node-mpv="github:pedromsilvapt/Node-MPV#83e9132acedbf7189ef349f46abd7a9e849713b3"

Why PkgRadar flagged 0.1.16

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.node-mpv="github:pedromsilvapt/Node-MPV#83e9132acedbf7189ef349f46abd7a9e849713b3" · package.json
mediumDependency Changed To Remote Vs Previousdependencies.node-mpv changed to remote spec in 0.1.16 vs 0.1.15: "github:pedromsilvapt/Node-MPV#83e9132acedbf7189ef349f46abd7a9e849713b3" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.15Low risk02026-06-07
0.1.16Review242026-06-07

Block this in CI

PkgRadar gates unicast-mpv (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]