PkgRadar

npm · registry.npmjs.org

@nubjs/nub

Install-time lifecycle script: postinstall="node postinstall.js"

Why PkgRadar flagged 0.0.26

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.0.26 vs 0.0.25: "node postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.34Review12026-06-12
0.0.33Review12026-06-11
0.0.32Review12026-06-11
0.0.31Review12026-06-10
0.0.30Review12026-06-10
0.0.29Review12026-06-10
0.0.28Review12026-06-10
0.0.27Review12026-06-10
0.0.26High risk452026-06-10
0.0.25Low risk02026-06-10
0.0.24Low risk02026-06-10
0.0.23Low risk02026-06-08
0.0.22Low risk02026-06-08
0.0.21Low risk02026-06-08
0.0.20Low risk02026-06-08
0.0.19Low risk02026-06-08
0.0.18Review12026-06-07
0.0.17Review12026-06-07
0.0.15Review12026-06-04
0.0.16Review12026-06-04
0.0.13Review12026-06-03
0.0.14Review12026-06-03
0.0.12Review12026-06-01
0.0.11Review12026-05-30
0.0.10Review12026-05-30
0.0.9Review12026-05-30
0.0.8Review12026-05-30
0.0.7Review12026-05-30
0.0.4Review102026-05-27
0.0.5Review102026-05-27

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @nubjs/nub (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @nubjs/[email protected]