npm · registry.npmjs.org
@lumifai/node-jq-native
Install Lifecycle Suppresses Failure: preinstall="chmod +x scripts/*.sh scripts/*.js || true"
Why PkgRadar flagged 1.0.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Install Lifecycle Suppresses Failure | preinstall="chmod +x scripts/*.sh scripts/*.js || true" · package.json |
| medium | Remote Payload | matched "github.com/kkos/oniguruma/releases/download" · package/deps/jq/compile-ios.sh |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.0.0 | High risk | 42 | 2026-06-09 |
1.1.0 | Review | 1 | 2026-06-09 |
1.2.1 | Review | 1 | 2026-06-09 |
1.2.2 | Review | 1 | 2026-06-09 |
Block this in CI
pkgradar gate --ecosystem npm @lumifai/[email protected]