npm · registry.npmjs.org
@alauda/custom-webpack
Install Lifecycle Remote Or Exec: postinstall="node -e \"require('fs').existsSync('.git') && require('child_process').execSync('patch-package && yarn schema && simple-git-hooks', {stdio:'inherit', shell:true})\""
Why PkgRadar flagged 5.2.10
| Severity | Signal | Evidence |
|---|---|---|
| high | Install Lifecycle Remote Or Exec | postinstall="node -e \"require('fs').existsSync('.git') && require('child_process').execSync('patch-package && yarn schema && simple-git-hooks', {stdio:'inherit', shell:true})\"" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
5.3.2 | Low risk | 0 | 2026-06-04 |
5.3.1-preview.135.e8104e2 | Low risk | 0 | 2026-06-04 |
5.3.1 | Low risk | 0 | 2026-06-03 |
5.3.0 | Low risk | 0 | 2026-06-03 |
5.2.10-preview.132.4acdd54 | Low risk | 0 | 2026-06-03 |
5.2.10-preview.132.803487e | Low risk | 0 | 2026-06-03 |
5.3.0-beta.0 | Low risk | 0 | 2026-06-03 |
5.2.10 | Review | 10 | 2026-06-03 |
5.3.0-beta | Low risk | 0 | 2026-06-03 |
Block this in CI
pkgradar gate --ecosystem npm @alauda/[email protected]