PkgRadar

npm · registry.npmjs.org

@c8y/api-doc

Remote Payload: matched "cURL\n "

Why PkgRadar flagged 1023.82.3

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL\n " · package/public/c8y-oas.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
1023.85.1Low risk02026-06-16
1023.83.4Low risk02026-06-04
1023.83.3Low risk02026-06-02
1023.83.2Low risk02026-06-01
1023.82.8Low risk02026-05-29
1023.82.3Review32026-05-25
1023.82.4Review32026-05-25

Block this in CI

PkgRadar gates @c8y/api-doc (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @c8y/[email protected]