PkgRadar

npm · registry.npmjs.org

@alicloud/ros-cdk-cli

Remote Payload: matched "curl "

Why PkgRadar flagged 1.11.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/lib/cdk-toolkit.js
mediumRemote Payloadmatched "curl " · package/lib/cdk-toolkit.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
1.11.0Review122026-06-16
1.0.52Review122026-06-16
1.12.0Review122026-06-16
1.13.0Review122026-06-16
1.0.51Review122026-06-16
1.0.50Review122026-06-16
1.14.0Review122026-06-16

Block this in CI

PkgRadar gates @alicloud/ros-cdk-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @alicloud/[email protected]