npm · registry.npmjs.org
@ocas/cli
Install Lifecycle Suppresses Failure: postinstall="bun scripts/postinstall.js || true"
Why PkgRadar flagged 0.1.2-rc.1
| Severity | Signal | Evidence |
|---|---|---|
| high | New Lifecycle Script Vs Previous | postinstall added in 0.1.2-rc.1 vs 0.1.1: "bun scripts/postinstall.js || true" · package.json |
| high | Install Lifecycle Suppresses Failure | postinstall="bun scripts/postinstall.js || true" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.5.0 | Low risk | 0 | 2026-06-10 |
0.1.2-rc.1 | High risk | 65 | 2026-06-10 |
0.4.0 | Low risk | 0 | 2026-06-07 |
0.3.1 | Low risk | 0 | 2026-06-04 |
0.3.0 | Low risk | 0 | 2026-06-03 |
0.2.2 | Low risk | 0 | 2026-06-03 |
0.2.1 | Low risk | 0 | 2026-06-03 |
0.2.0-rc.1 | Low risk | 0 | 2026-06-02 |
0.2.0 | Low risk | 0 | 2026-06-02 |
0.1.2 | Low risk | 0 | 2026-06-02 |
0.1.2-rc.2 | Low risk | 0 | 2026-06-02 |
0.1.1 | Low risk | 0 | 2026-06-02 |
0.1.1-rc.2 | Low risk | 0 | 2026-06-02 |
0.1.1-rc.1 | Low risk | 0 | 2026-06-02 |
0.1.0 | Low risk | 0 | 2026-06-01 |
0.1.0-alpha.1 | Low risk | 0 | 2026-06-01 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem npm @ocas/[email protected]