Known-risky / deprecated package
Part of the Dependency supply chain check · fix arrives as a guide
What it is
A dependency is deprecated by its author, has known-bad releases, or is a package flagged as risky — including typosquat-shaped names close to a popular package.
Why it matters
A deprecated package stops receiving security fixes while continuing to work, so nothing prompts you to move. A typosquatted name is worse: it was installed by accident and does whatever its author chose.
How to fix it
Confirm the package is the one you meant, then move to the maintained successor the deprecation notice names. Where no successor exists, vendor the small piece you use rather than depending on an unmaintained tree.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.