PkgRadar

npm · registry.npmjs.org

@camunda8/cli

Install Lifecycle Remote Or Exec: prepare="git rev-parse --is-inside-work-tree >/dev/null 2>&1 && sh -c 'hp=$(git config --local --get core.hooksPath 2>/dev/null || true); if [ -z \"$hp\" ] || [ \"$hp\" = \".githooks\" ]; then git config --local core.hooksPath .githooks; else echo \"prepare: leaving existing core.hooksPath=$hp\"; fi' || true"

Why PkgRadar flagged 3.2.0-alpha.2

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execprepare="git rev-parse --is-inside-work-tree >/dev/null 2>&1 && sh -c 'hp=$(git config --local --get core.hooksPath 2>/dev/null || true); if [ -z \"$hp\" ] || [ \"$hp\" = \".githooks\" ]; then git config --local core.hooksPath .githooks; else echo \"prepare: leaving existing core.hooksPath=$hp\"; fi' || true" · package.json
highInstall Lifecycle Suppresses Failureprepare="git rev-parse --is-inside-work-tree >/dev/null 2>&1 && sh -c 'hp=$(git config --local --get core.hooksPath 2>/dev/null || true); if [ -z \"$hp\" ] || [ \"$hp\" = \".githooks\" ]; then git config --local core.hooksPath .githooks; else echo \"prepare: leaving existing core.hooksPath=$hp\"; fi' || true" · package.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/default-plugins/element-template/c8ctl-plugin.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/default-plugins/element-template/helpers.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/default-plugins/element-template/marketplace.js
mediumLarge Javascript Payload2368802 bytes · package/dist/vendor/bpmn-element-templates.cjs

Scanned versions

VersionVerdictScoreScanned (UTC)
3.2.0-alpha.10Low risk02026-06-04
3.2.0-alpha.9Low risk02026-06-04
3.2.0-alpha.8Low risk02026-06-03
3.2.0-alpha.7Low risk02026-05-31
3.2.0-alpha.6Low risk02026-05-30
3.2.0-alpha.5Low risk02026-05-30
3.2.0-alpha.4Low risk02026-05-29
3.2.0-alpha.2Review962026-05-25
3.2.0-alpha.3Review962026-05-25

Related campaigns

Block this in CI

PkgRadar gates @camunda8/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @camunda8/[email protected]