PkgRadar

npm · registry.npmjs.org

whatsapp-rust-bridge

Remote Dependency Spec: devDependencies.@whiskeysockets/libsignal-node="git+https://github.com/whiskeysockets/libsignal-node"

Why PkgRadar flagged 0.6.0-alpha.36

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.@whiskeysockets/libsignal-node="git+https://github.com/whiskeysockets/libsignal-node" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.0-alpha.36Review22026-06-02
0.6.0-alpha.35Review52026-06-01
0.6.0-alpha.34Review22026-06-01
0.6.0-alpha.33Review22026-05-30
0.6.0-alpha.32Review52026-05-29
0.6.0-alpha.31Review22026-05-29
0.6.0-alpha.29Review52026-05-29
0.6.0-alpha.30Review52026-05-29

Block this in CI

PkgRadar gates whatsapp-rust-bridge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]