PkgRadar

npm · registry.npmjs.org

@bufbuild/buf

Install-time lifecycle script: postinstall="node ./install.js"

Scanned versions

VersionVerdictScoreScanned (UTC)
1.68.4Review12026-06-16
1.71.0Review12026-06-16
1.69.0Review102026-05-25
1.70.0Review102026-05-25

Block this in CI

PkgRadar gates @bufbuild/buf (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bufbuild/[email protected]