PkgRadar

npm · registry.npmjs.org

@0x/subproviders

Install Lifecycle Remote Or Exec: postinstall="node -e \"try{ fs.unlinkSync(path.resolve(path.dirname(require.resolve('ganache-core')), './typings/index.d.ts')) } catch (err) {}\""

Why PkgRadar flagged 6.6.5

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try{ fs.unlinkSync(path.resolve(path.dirname(require.resolve('ganache-core')), './typings/index.d.ts')) } catch (err) {}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
6.6.5High risk172026-06-11
7.0.0Review22026-06-11
7.0.1Review22026-06-11
8.0.1Review22026-06-11

Block this in CI

PkgRadar gates @0x/subproviders (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @0x/[email protected]