Per the Socket.dev case study: install scripts are often legitimate; direct GitHub dependencies should be pinned or replaced with registry versions.

Context: Problem: Two alert types need different responses. installScripts on electron is expected behavior - the package needs a postinstall script to download its binary. gitHubDependency is a real risk signal: the package depends directly on a GitHub repo that could be deleted or rewritten - check whether an npm release exists and switch to it, or pin to a specific commit.