PkgRadar

npm · registry.npmjs.org

@makefinks/daemon

Credential file access: matched ".config/gcloud"

Why PkgRadar flagged 0.17.0

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.17.0 vs 0.16.0: "bash ./scripts/patch-mem0ai.sh" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.17.0High risk502026-06-10
0.17.2Review102026-06-08
0.17.1Review102026-06-07
0.16.0Review52026-06-04
0.15.0Review52026-06-03
0.14.3Review52026-06-02
0.14.2Review52026-05-31
0.14.1Review52026-05-31
0.13.0Review52026-05-31
0.14.0Review52026-05-31

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @makefinks/daemon (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @makefinks/[email protected]