PkgRadar

npm · registry.npmjs.org

@heymp/scratchpad

Install-time lifecycle script: preinstall="echo 'Do not run yarn install directly. Use: yarn setup' && exit 1"

Why PkgRadar flagged 1.0.0-next.22

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspreinstall added in 1.0.0-next.22 vs 1.0.0-next.20: "echo 'Do not run yarn install directly. Use: yarn setup' && exit 1" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0-next.10Low risk02026-06-10
1.0.0-next.18Low risk02026-06-10
1.0.0-next.19Low risk02026-06-10
1.0.0-next.20Low risk02026-06-10
1.0.0-next.22High risk452026-06-10

Block this in CI

PkgRadar gates @heymp/scratchpad (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @heymp/[email protected]