Source code Security & compliance Code quality

Known-risky / deprecated package

Part of the Dependency supply chain check · fix arrives as a guide

What it is

A dependency is deprecated by its author, has known-bad releases, or is a package flagged as risky — including typosquat-shaped names close to a popular package.

Why it matters

A deprecated package stops receiving security fixes while continuing to work, so nothing prompts you to move. A typosquatted name is worse: it was installed by accident and does whatever its author chose.

How to fix it

Confirm the package is the one you meant, then move to the maintained successor the deprecation notice names. Where no successor exists, vendor the small piece you use rather than depending on an unmaintained tree.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.