PkgRadar

npm · registry.npmjs.org

@compilr-dev/sdk

Remote Payload: matched "curl "

Why PkgRadar flagged 0.10.17

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/meta-tools/registry.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.14.0Low risk02026-06-14
0.12.0Low risk02026-06-13
0.13.0Low risk02026-06-13
0.11.0Low risk02026-06-13
0.10.40Low risk02026-06-07
0.10.41Low risk02026-06-07
0.10.39Low risk02026-06-07
0.10.38Low risk02026-06-07
0.10.36Low risk02026-06-07
0.10.37Low risk02026-06-07
0.10.35Low risk02026-06-06
0.10.34Low risk02026-06-06
0.10.33Low risk02026-06-06
0.10.32Low risk02026-06-05
0.10.31Low risk02026-06-05
0.10.30Low risk02026-06-04
0.10.29Low risk02026-06-04
0.10.28Low risk02026-06-04
0.10.23Low risk02026-06-04
0.10.22Low risk02026-06-04
0.10.21Low risk02026-06-03
0.10.19Low risk02026-06-01
0.10.20Low risk02026-06-01
0.10.18Low risk02026-06-01
0.10.17Review122026-05-25
0.10.16Review242026-05-25
0.10.15Review242026-05-24
0.10.14Review242026-05-24
0.10.13Review242026-05-24
0.10.12Review242026-05-24
0.10.10Review242026-05-24
0.10.11Review242026-05-24

Block this in CI

PkgRadar gates @compilr-dev/sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @compilr-dev/[email protected]