PkgRadar

npm · registry.npmjs.org

@amazon-devices/react-native-fast-image

Install Lifecycle Remote Or Exec: postinstall="find . -type f -name \"libkeplerscript-stable-fast-image-lib-8.so\" -exec sh -c 'for f; do d=$(dirname \"$f\"); b=$(basename \"$f\"); ln -sf \"$b\" \"${d}/com.amazon.kepler.uitoolkit.react.fastimage.so\"; done' sh {} +"

Why PkgRadar flagged 3.0.12-rn-83

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="find . -type f -name \"libkeplerscript-stable-fast-image-lib-8.so\" -exec sh -c 'for f; do d=$(dirname \"$f\"); b=$(basename \"$f\"); ln -sf \"$b\" \"${d}/com.amazon.kepler.uitoolkit.react.fastimage.so\"; done' sh {} +" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.1759135970Low risk02026-06-12
3.0.12-rn-83High risk242026-06-12
3.0.6High risk752026-06-12
3.0.7High risk242026-06-12

Block this in CI

PkgRadar gates @amazon-devices/react-native-fast-image (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @amazon-devices/[email protected]