PkgRadar

npm · registry.npmjs.org

@newpeak/barista-cli

Install-time lifecycle script: postinstall="node scripts/postinstall.js"

Why PkgRadar flagged 0.2.60

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.2.60 vs 0.2.59: "node scripts/postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.60High risk452026-06-20
0.2.55Low risk02026-06-19
0.2.59Low risk02026-06-19
0.2.51Low risk02026-06-19
0.2.35Low risk02026-06-18
0.2.37Low risk02026-06-18
0.2.28Low risk02026-06-17
0.2.24Low risk02026-06-17
0.2.8Low risk02026-06-16
0.2.5Low risk02026-06-16
0.2.3Low risk02026-06-14
0.1.748Low risk02026-06-14
0.1.745Low risk02026-06-14
0.1.742Low risk02026-06-14
0.1.737Low risk02026-06-13
0.1.735Low risk02026-06-13
0.1.728Low risk02026-06-13
0.1.723Low risk02026-06-12
0.1.714Low risk02026-06-12
0.1.704Low risk02026-06-11
0.1.698Low risk02026-06-11
0.1.696Low risk02026-06-11
0.1.693Low risk02026-06-11
0.1.685Low risk02026-06-10
0.1.682Low risk02026-06-10
0.1.679Low risk02026-06-09
0.1.676Low risk02026-06-09
0.1.674Low risk02026-06-09
0.1.670Low risk02026-06-09
0.1.650Low risk02026-06-08
0.1.637Low risk02026-06-08
0.1.630Low risk02026-06-07
0.1.627Low risk02026-06-07
0.1.624Low risk02026-06-07
0.1.622Low risk02026-06-06
0.1.609Low risk02026-06-06
0.1.605Low risk02026-06-06
0.1.603Low risk02026-06-06
0.1.601Low risk02026-06-06
0.1.599Low risk02026-06-06
0.1.597Low risk02026-06-05
0.1.589Low risk02026-06-05
0.1.584Low risk02026-06-05
0.1.580Low risk02026-06-05
0.1.572Low risk02026-06-05
0.1.560Low risk02026-06-04
0.1.556Low risk02026-06-04
0.1.551Low risk02026-06-04
0.1.549Low risk02026-06-04
0.1.546Low risk02026-06-04
0.1.538Low risk02026-06-03
0.1.528Low risk02026-06-03
0.1.516Low risk02026-06-02
0.1.501Low risk02026-06-02
0.1.496Low risk02026-06-02
0.1.495Low risk02026-06-02
0.1.491Low risk02026-06-02
0.1.479Low risk02026-06-01
0.1.478Low risk02026-05-31
0.1.476Low risk02026-05-31
0.1.473Low risk02026-05-31
0.1.470Low risk02026-05-30
0.1.463Low risk02026-05-30
0.1.462Low risk02026-05-29
0.1.461Low risk02026-05-29
0.1.457Low risk02026-05-28
0.1.455Low risk02026-05-27
0.1.450Low risk02026-05-27
0.1.447Low risk02026-05-26
0.1.448Low risk02026-05-26
0.1.439Low risk02026-05-26
0.1.429Low risk02026-05-25
0.1.424Low risk02026-05-25
0.1.423Low risk02026-05-24
0.1.408Low risk02026-05-24
0.1.362Low risk02026-05-24
0.1.397Low risk02026-05-24

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @newpeak/barista-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @newpeak/[email protected]