PkgRadar

npm · registry.npmjs.org

@harness-engineering/core

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.29.0

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/index.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/index.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.29.0Review72026-06-03
0.28.2Review102026-05-27
0.28.0Review232026-05-27
0.28.1Review102026-05-27

Block this in CI

PkgRadar gates @harness-engineering/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @harness-engineering/[email protected]