PkgRadar

npm · registry.npmjs.org

@forge/cli

Install Lifecycle Remote Or Exec: postinstall="node -e \"fs.existsSync('./out/bin/postinstall.js') && require('./out/bin/postinstall.js')\""

Why PkgRadar flagged 12.21.0-experimental-4a332af

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"fs.existsSync('./out/bin/postinstall.js') && require('./out/bin/postinstall.js')\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
12.21.0-experimental-4a332afReview102026-06-01
12.21.0Review102026-05-30
12.21.0-next.8-experimental-2e302e1Review102026-05-30
12.21.0-next.13Review102026-05-30

Block this in CI

PkgRadar gates @forge/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @forge/[email protected]