PkgRadar

npm · registry.npmjs.org

yomitan-core

Remote Dependency Spec: dependencies.yomitan-handlebars="git+https://github.com/yomidevs/yomitan-handlebars.git#12aff5e3550954d7d3a98a5917ff7d579f3cce25"

Why PkgRadar flagged 1.5.0

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.yomitan-handlebars="git+https://github.com/yomidevs/yomitan-handlebars.git#12aff5e3550954d7d3a98a5917ff7d579f3cce25" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.0Review32026-06-01
1.4.0Review32026-06-01
1.5.0-pr.1.26730003268.1Review32026-06-01

Block this in CI

PkgRadar gates yomitan-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]