PkgRadar

npm · registry.npmjs.org

@exellix/exellix-runtime

Install-time lifecycle script: postinstall="node node_modules/@exellix/graph-engine/scripts/patch-ai-tasks-xynthesis-export.mjs"

Why PkgRadar flagged 3.8.2

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 3.8.2 vs 3.7.2: "node node_modules/@exellix/graph-engine/scripts/patch-ai-tasks-xynthesis-export.mjs" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
5.1.9Low risk02026-06-12
3.8.2High risk452026-06-10
5.1.8Low risk02026-06-09
5.1.7Low risk02026-06-09
5.1.4Low risk02026-06-08
5.1.3Low risk02026-06-08
5.1.2Low risk02026-06-07
5.1.1Low risk02026-06-07
5.1.0Low risk02026-06-07
5.0.0Low risk02026-06-06
4.4.2Low risk02026-06-05
4.4.1Low risk02026-06-05
4.4.0Low risk02026-06-05
4.3.9Low risk02026-06-04
4.3.8Low risk02026-06-04
4.3.7Low risk02026-06-04
4.3.4Low risk02026-06-04
4.3.5Low risk02026-06-04
4.3.2Low risk02026-06-03
4.3.1Low risk02026-06-03
4.3.0Low risk02026-06-01
4.2.4Low risk02026-05-31
4.2.3Low risk02026-05-31
4.2.2Low risk02026-05-31
4.2.1Low risk02026-05-31
4.2.0Low risk02026-05-31
4.1.10Low risk02026-05-31
4.1.9Low risk02026-05-31
4.1.8Low risk02026-05-31
4.1.7Low risk02026-05-31
4.1.3Low risk02026-05-31
4.1.1Low risk02026-05-30
4.1.0Low risk02026-05-30
4.0.3Low risk02026-05-30
4.0.2Low risk02026-05-30
3.9.7Low risk02026-05-30
3.9.0Low risk02026-05-30
3.8.6Review32026-05-30
3.7.2Low risk02026-05-30
3.7.1Low risk02026-05-30
3.7.0Low risk02026-05-30
3.6.2Low risk02026-05-30
4.0.1Low risk02026-05-29
3.9.9Low risk02026-05-29
4.0.0Low risk02026-05-29

Related campaigns

Block this in CI

PkgRadar gates @exellix/exellix-runtime (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @exellix/[email protected]