PkgRadar

npm · registry.npmjs.org

@hanzogui/native-ci

Remote Payload: matched "curl "

Why PkgRadar flagged 7.3.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/deps.mjs
mediumRemote Payloadmatched "curl " · package/src/deps.ts
mediumRemote Payloadmatched "curl " · package/src/ios.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
7.3.0Review362026-06-08
2.0.0-rc.41-hanzoai.5Review362026-06-08
4.4.0Review362026-06-08
102.0.0-rc.41-hanzoai.1Review502026-05-24
7.0.0Review502026-05-24

Block this in CI

PkgRadar gates @hanzogui/native-ci (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hanzogui/[email protected]