PkgRadar

npm · registry.npmjs.org

vellum

Remote Payload: matched "github.com/qdrant/qdrant/releases/download"

Why PkgRadar flagged 0.2.12

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/qdrant/qdrant/releases/download" · package/src/memory/qdrant-manager.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.10-dev.202606111245.be4218bLow risk02026-06-11
0.8.10-dev.202606111140.6a5e88cLow risk02026-06-11
0.8.10-dev.202606110941.6cb149dLow risk02026-06-11
0.8.10-dev.202606110755.6cb149dLow risk02026-06-11
0.8.10-dev.202606110544.2aed335Low risk02026-06-11
0.8.10-dev.202606110422.8c0e9aaLow risk02026-06-11
0.8.10-dev.202606110317.792ac3cLow risk02026-06-11
0.8.10-dev.202606110240.ef9212eLow risk02026-06-11
0.8.10-dev.202606110112.319a8d3Low risk02026-06-11
0.8.10-dev.202606110059.319a8d3Low risk02026-06-11
0.8.10-dev.202606102342.319a8d3Low risk02026-06-10
0.8.10-dev.202606102253.fbea648Low risk02026-06-10
0.8.10-dev.202606102242.5285563Low risk02026-06-10
0.8.10-dev.202606102225.a3947deLow risk02026-06-10
0.8.10-dev.202606102147.02afd31Low risk02026-06-10
0.8.10-dev.202606102100.3beeffcLow risk02026-06-10
0.8.10-dev.202606101903.31e26e6Low risk02026-06-10
0.8.10-dev.202606101714.d4b22deLow risk02026-06-10
0.8.10-dev.202606101514.1c52cedLow risk02026-06-10
0.8.10-dev.202606101324.2fc90b3Low risk02026-06-10
0.8.10-dev.202606101436.d73da44Low risk02026-06-10
0.8.10-dev.202606101122.0de2affLow risk02026-06-10
0.8.10-dev.202606100925.28c1cfbLow risk02026-06-10
0.8.10-dev.202606100742.99a7fabLow risk02026-06-10
0.8.10-dev.202606100317.c8b43c8Low risk02026-06-10
0.8.10-dev.202606100540.99a7fabLow risk02026-06-10
0.2.12Review52026-06-10
0.2.13Review52026-06-10
0.2.14Review102026-06-10
0.8.10-dev.202606100110.1d2c8c4Low risk02026-06-10
0.8.10-dev.202606092334.09948c8Low risk02026-06-09
0.8.10-dev.202606092238.d04fd59Low risk02026-06-09
0.8.10Low risk02026-06-09
0.8.9-dev.202606092139.1f3b646Low risk02026-06-09
0.8.9-dev.202606092047.e63da55Low risk02026-06-09
0.8.10-staging.1Low risk02026-06-09
0.8.9-dev.202606091946.122706eLow risk02026-06-09
0.8.9-dev.202606091926.ebb2d62Low risk02026-06-09
0.8.9-dev.202606091853.fbaa2aeLow risk02026-06-09
0.8.9Low risk02026-06-09
0.8.8-dev.202606091702.2771079Low risk02026-06-09
0.8.9-staging.5Low risk02026-06-09
0.8.8-dev.202606091516.3c27bebLow risk02026-06-09
0.8.8-dev.202606091311.113d87fLow risk02026-06-09
0.8.9-staging.4Low risk02026-06-09
0.8.8-dev.202606090339.ad6ec5aLow risk02026-06-09
0.8.8-dev.202606090318.74794feLow risk02026-06-09
0.8.8-dev.202606090227.d9f1d29Low risk02026-06-09
0.8.8-dev.202606090218.6bcb462Low risk02026-06-09
0.8.8-dev.202606090104.b75d235Low risk02026-06-09
0.8.8-dev.202606082331.c911d0cLow risk02026-06-09
0.8.8-dev.202606082236.8dbacc9Low risk02026-06-08
0.8.9-staging.3Low risk02026-06-08
0.8.8-dev.202606082140.a5125feLow risk02026-06-08
0.8.8-dev.202606082058.447e3b6Low risk02026-06-08
0.8.8-dev.202606081950.5bd40e7Low risk02026-06-08
0.8.8-dev.202606081859.f7bdc00Low risk02026-06-08
0.8.8-dev.202606081714.5590368Low risk02026-06-08
0.8.9-staging.2Low risk02026-06-08
0.8.8-dev.202606081339.938c6ecLow risk02026-06-08
0.8.8-dev.202606081515.c77a9b6Low risk02026-06-08
0.8.9-staging.1Low risk02026-06-08
0.8.8-dev.202606081143.f600053Low risk02026-06-08
0.8.8-dev.202606080544.8b7fbffLow risk02026-06-08
0.8.8-dev.202606080320.8b7fbffLow risk02026-06-08
0.8.8-dev.202606080112.5f6d567Low risk02026-06-08
0.8.8-dev.202606080009.0babb76Low risk02026-06-08
0.8.8-dev.202606072328.6710d73Low risk02026-06-08
0.8.8-dev.202606072131.4817a81Low risk02026-06-07
0.8.8-dev.202606072033.0e97ff6Low risk02026-06-07
0.8.8-dev.202606071935.547b6d2Low risk02026-06-07
0.8.8-dev.202606071835.08695c1Low risk02026-06-07
0.8.8-dev.202606071734.db66b83Low risk02026-06-07
0.8.8-dev.202606071535.f449fc1Low risk02026-06-07
0.8.8-dev.202606071441.cfe7f13Low risk02026-06-07
0.8.8-dev.202606071338.2b9914eLow risk02026-06-07
0.8.8-dev.202606071242.4ca7f3bLow risk02026-06-07
0.8.8-dev.202606071138.c258385Low risk02026-06-07
0.8.8-dev.202606071051.c258385Low risk02026-06-07
0.8.8-dev.202606070049.ca91213Low risk02026-06-07
0.8.8-dev.202606062128.ca91213Low risk02026-06-06
0.8.8-dev.202606062031.571ee14Low risk02026-06-06
0.8.8-dev.202606061935.99a472fLow risk02026-06-06
0.8.8-dev.202606061835.dc283b1Low risk02026-06-06
0.8.8-dev.202606061731.f1025b0Low risk02026-06-06
0.8.8-dev.202606061714.60a1761Low risk02026-06-06
0.8.8-dev.202606061701.9ee494cLow risk02026-06-06
0.8.8-dev.202606061631.10cd5feLow risk02026-06-06
0.8.8-dev.202606061533.1a66375Low risk02026-06-06
0.8.8-dev.202606061135.a446a08Low risk02026-06-06
0.8.8-dev.202606061043.373bc8fLow risk02026-06-06
0.8.8-dev.202606060901.61e1660Low risk02026-06-06
0.8.8-dev.202606060043.60454adLow risk02026-06-06
0.8.8-dev.202606052332.17fc8eaLow risk02026-06-05
0.8.8Low risk02026-06-05
0.8.7-dev.202606052232.2ddc989Low risk02026-06-05
0.8.7-dev.202606052220.6efc86dLow risk02026-06-05
0.8.7-dev.202606052135.3e62c5aLow risk02026-06-05
0.8.7-dev.202606052118.34cd356Low risk02026-06-05
0.8.7Low risk02026-06-03
0.8.6Low risk02026-05-29
0.8.5Low risk02026-05-27
0.8.4Low risk02026-05-27

Block this in CI

PkgRadar gates vellum (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]