PkgRadar

npm · registry.npmjs.org

@hasna/mementos

Install Lifecycle Suppresses Failure: postinstall="mkdir -p $HOME/.hasna/mementos $HOME/.hasna/mementos/profiles $HOME/.hasna/mementos/agents $HOME/.hasna/mementos/training 2>/dev/null || true"

Why PkgRadar flagged 0.14.35

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="mkdir -p $HOME/.hasna/mementos $HOME/.hasna/mementos/profiles $HOME/.hasna/mementos/agents $HOME/.hasna/mementos/training 2>/dev/null || true" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.14.35High risk212026-06-10
0.14.34High risk702026-06-10
0.14.37High risk172026-06-10
0.14.36High risk252026-06-10
0.14.21High risk212026-06-10
0.14.20High risk212026-06-10
0.14.33Low risk02026-05-28
0.14.29Low risk02026-05-27
0.14.30Low risk02026-05-27

Block this in CI

PkgRadar gates @hasna/mementos (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hasna/[email protected]