PkgRadar

npm · registry.npmjs.org

@haus-tech/haus-workflow

Install Lifecycle Suppresses Failure: postinstall="node ./scripts/postinstall.mjs || true"

Why PkgRadar flagged 0.12.0

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.12.0 vs 0.11.1: "node ./scripts/postinstall.mjs || true" · package.json
highInstall Lifecycle Suppresses Failurepostinstall="node ./scripts/postinstall.mjs || true" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.25.0Review92026-06-12
0.24.1Review92026-06-12
0.24.0Review92026-06-12
0.23.1Review92026-06-12
0.23.0Review92026-06-12
0.22.1Review92026-06-11
0.22.0Review92026-06-11
0.21.0Review92026-06-11
0.20.0Review92026-06-11
0.19.0Review92026-06-11
0.18.2Review92026-06-11
0.12.0High risk702026-06-10
0.18.1Review92026-06-09
0.18.0Review92026-06-09
0.17.0Review92026-06-09
0.17.1Review92026-06-09
0.16.3Review92026-06-09
0.16.2Review92026-06-09
0.16.1Review92026-06-09
0.16.0Review92026-06-05
0.15.0Review92026-06-05
0.14.0Review92026-06-04
0.13.2Review92026-06-04
0.13.1Review92026-06-03
0.13.0Review92026-06-03
0.12.1Review92026-06-03
0.11.1Review12026-06-01
0.11.0Review12026-06-01
0.10.1Review12026-05-29
0.10.0Review12026-05-29
0.9.0Review12026-05-28
0.8.0Review12026-05-28
0.1.0Review52026-05-27

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @haus-tech/haus-workflow (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @haus-tech/[email protected]