npm · registry.npmjs.org
@heroku/ember-hk-components
Install-time lifecycle script: preinstall="npx only-allow pnpm"
Why PkgRadar flagged 1.21.3
| Severity | Signal | Evidence |
|---|---|---|
| high | New Lifecycle Script Vs Previous | preinstall added in 1.21.3 vs 0.21.2: "npx only-allow pnpm" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.21.0 | Low risk | 0 | 2026-06-11 |
0.21.1 | Low risk | 0 | 2026-06-11 |
0.21.2 | Low risk | 0 | 2026-06-11 |
1.21.3 | High risk | 45 | 2026-06-11 |
1.21.4 | Review | 2 | 2026-05-27 |
1.21.5 | Review | 2 | 2026-05-27 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem npm @heroku/[email protected]