PkgRadar

npm · registry.npmjs.org

@dimina-kit/devkit

Remote Payload: matched "curl "

Why PkgRadar flagged 0.1.2-dev.20260524102544

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/fe/dimina-fe-container/assets/pageFrame.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.2-dev.20260616102751Low risk02026-06-16
0.1.2-dev.20260616085026Low risk02026-06-16
0.1.2-dev.20260616024534Low risk02026-06-16
0.1.2-dev.20260615083030Low risk02026-06-15
0.1.2-dev.20260615070430Low risk02026-06-15
0.1.2-dev.20260612152115Low risk02026-06-12
0.1.2-dev.20260612025610Low risk02026-06-12
0.1.2-dev.20260611135124Low risk02026-06-11
0.1.2-dev.20260611063505Low risk02026-06-11
0.1.2-dev.20260611060732Low risk02026-06-11
0.1.2-dev.20260610114009Low risk02026-06-10
0.1.1Low risk02026-06-10
0.1.2-dev.20260610082053Low risk02026-06-10
0.1.2-dev.20260601115343Low risk02026-06-01
0.1.2-dev.20260524104239Low risk02026-05-25
0.1.2-dev.20260525152421Low risk02026-05-25
0.1.2-dev.20260524102544Review122026-05-24
0.1.2-dev.20260522142649Review122026-05-24

Block this in CI

PkgRadar gates @dimina-kit/devkit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @dimina-kit/[email protected]