PkgRadar

npm · registry.npmjs.org

@lumerahq/cli

Remote Payload: matched "curl "

Why PkgRadar flagged 0.19.18

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/init-HUV5ZJAE.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.19.18Review32026-06-12
0.19.17Review32026-06-11
0.19.16Review32026-06-11
0.19.17-dev.0Review32026-06-11
0.19.16-dev.0Review32026-06-10
0.19.15Review32026-06-05
0.19.14Review32026-06-04
0.19.13Review32026-06-04
0.19.12Review32026-06-03
0.19.10Review122026-06-03
0.19.11Review32026-06-03

Block this in CI

PkgRadar gates @lumerahq/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @lumerahq/[email protected]