PkgRadar

npm · registry.npmjs.org

@palettelab/cli

Remote Payload: matched "github.com/palette-lab/palette-virtual-organization-backend/releases/download"

Why PkgRadar flagged 0.3.47

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/palette-lab/palette-virtual-organization-backend/releases/download" · package/template-fallback/pyproject.toml

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.59Low risk02026-06-16
0.3.58Low risk02026-06-12
0.3.57Low risk02026-06-12
0.3.56Low risk02026-06-12
0.3.55Low risk02026-06-10
0.3.54Low risk02026-06-05
0.3.53Low risk02026-05-28
0.3.52Low risk02026-05-28
0.3.51Low risk02026-05-26
0.3.50Low risk02026-05-26
0.3.49Low risk02026-05-25
0.3.47Review122026-05-25
0.3.48Review122026-05-25

Block this in CI

PkgRadar gates @palettelab/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @palettelab/[email protected]