npm · registry.npmjs.org
@atlassian-dc-mcp/bitbucket
Remote Payload: matched "curl "
Why PkgRadar flagged 0.19.0
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "curl " · package/build/bitbucket-client/services/ProjectService.js |
| medium | Remote Payload | matched "curl " · package/build/bitbucket-client/services/RepositoryService.js |
| medium | Remote Payload | matched "curl " · package/build/bitbucket-client/services/SystemMaintenanceService.js |
| medium | Remote Payload | matched "curl " · package/src/bitbucket-client/services/ProjectService.ts |
| medium | Remote Payload | matched "curl " · package/src/bitbucket-client/services/RepositoryService.ts |
| medium | Remote Payload | matched "curl " · package/src/bitbucket-client/services/SystemMaintenanceService.ts |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.18.0 | Low risk | 0 | 2026-06-08 |
0.20.0 | Low risk | 0 | 2026-06-08 |
0.19.0 | Review | 50 | 2026-05-24 |
0.19.1 | Review | 50 | 2026-05-24 |
Related campaigns
- evgeniy.moroz — 6 releases, max score 50
Block this in CI
pkgradar gate --ecosystem npm @atlassian-dc-mcp/[email protected]