PkgRadar

npm · registry.npmjs.org

@bbc/sofie-openapi

Remote Payload: matched "cUrl\n "

Why PkgRadar flagged 26.3.0-nightly-bbc-main-20260515-152934-b4a031f.0

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl\n " · package/api/definitions/ingest.yaml

Scanned versions

VersionVerdictScoreScanned (UTC)
26.3.0-nightly-bbc-main-autonext-20260611-150009-28cd6f2.0Low risk02026-06-11
1.53.0-nightly-bbc-release53-a9ae5e2-20251112-104105.0Low risk02026-06-11
26.3.0-nightly-bbc-main-autonext-20260603-124651-f5493c7.0Low risk02026-06-03
26.3.0-nightly-main-20260602-094633-1655232.0Low risk02026-06-02
26.3.0-nightly-bbc-main-20260602-095551-55a0153.0Low risk02026-06-02
26.3.0-nightly-bbc-main-20260515-152934-b4a031f.0Review32026-05-27
26.3.0-nightly-bbc-main-20260527-094000-5dbe905.0Review32026-05-27

Block this in CI

PkgRadar gates @bbc/sofie-openapi (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bbc/[email protected]