PkgRadar

npm · registry.npmjs.org

@cubejs-backend/testing

Remote Payload: matched "curl "

Why PkgRadar flagged 1.6.50

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/birdbox-fixtures/questdb/scripts/questdb-load-events.sh
mediumRemote Payloadmatched "curl " · package/birdbox-fixtures/materialize.yml
mediumRemote Payloadmatched "curl " · package/birdbox-fixtures/questdb.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.59Low risk02026-06-17
1.6.58Low risk02026-06-17
1.6.57Low risk02026-06-09
1.6.56Low risk02026-06-08
1.4.3Low risk02026-06-08
1.6.55Low risk02026-06-05
1.6.54Low risk02026-06-04
1.6.53Low risk02026-06-02
1.6.52Low risk02026-05-29
1.6.50Review102026-05-27
1.6.51Review102026-05-27

Block this in CI

PkgRadar gates @cubejs-backend/testing (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @cubejs-backend/[email protected]