PkgRadar

npm · registry.npmjs.org

@holdyourvoice/hyv

Install-time lifecycle script: postinstall="node scripts/postinstall.js"

Why PkgRadar flagged 2.4.1

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 2.4.1 vs 2.4.0: "node scripts/postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.9.10Review32026-06-13
2.9.9Review32026-06-12
2.9.8Review32026-06-12
2.9.7Review32026-06-12
2.9.6Review32026-06-12
2.9.5Review32026-06-12
2.9.4Review32026-06-12
2.9.3Review32026-06-12
2.9.1Review32026-06-12
2.9.2Review32026-06-12
2.9.0Review32026-06-12
2.8.10Review32026-06-12
2.8.9Review32026-06-12
2.8.7Review32026-06-12
2.8.8Review32026-06-12
2.8.6Review32026-06-12
2.8.5Review32026-06-12
2.8.3Review32026-06-12
2.8.4Review32026-06-12
2.8.2Review32026-06-12
2.8.1Review32026-06-12
2.8.0Review32026-06-12
2.7.1Review32026-06-11
2.7.0Review32026-06-11
2.6.0Review32026-06-11
2.5.0Review32026-06-11
2.5.1Review32026-06-11
2.4.5Review32026-06-11
2.4.1High risk452026-06-10
2.2.0High risk452026-06-10
2.0.1High risk752026-06-10
0.7.8High risk352026-06-10
0.7.7High risk242026-06-10
0.7.6High risk352026-06-10
0.7.5High risk242026-06-10
0.7.4High risk242026-06-10
0.7.3High risk242026-06-10
0.7.2High risk242026-06-10
0.7.1High risk752026-06-10
2.4.4Review52026-06-09
2.4.3Review32026-06-08
2.4.2Review52026-06-08
2.4.0Low risk02026-06-08
2.3.1Review32026-06-06
2.3.0Review32026-06-06
2.1.1Low risk02026-06-06
2.1.0Low risk02026-06-06
2.0.0Low risk02026-06-03
0.7.0Low risk02026-06-02
0.6.0Low risk02026-06-01
0.5.0Low risk02026-06-01
0.3.0Low risk02026-06-01
0.4.0Low risk02026-06-01
0.2.0Low risk02026-06-01
0.1.1Low risk02026-06-01
0.1.0Low risk02026-06-01
0.0.2Low risk02026-05-31
0.0.1Low risk02026-05-31

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @holdyourvoice/hyv (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @holdyourvoice/[email protected]