Loading npm security reports…
A comprehensive monorepo package management tool that maintains synchronized versions across all packages (lockstep versioning) with flexible CI/CD integration.
Explicit `lockstep publish` can execute shell syntax embedded in `--tag`, `--access`, or the current Git branch name. This is a command-injection vulnerability, not evidence of intentional package malware.
Package source references dynamic require/import behavior.
dist/changelog/llm-provider.jsView on unpkg · L39Package source references dynamic require/import behavior.
dist/changelog/llm-provider.jsView on unpkg · L39