PkgRadar

npm · registry.npmjs.org

@persona/relay

Install Lifecycle Suppresses Failure: postinstall="test -d .git && git config core.hooksPath .githooks || true"

Why PkgRadar flagged 0.1.3

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.1.3 vs 0.1.2: "test -d .git && git config core.hooksPath .githooks || true" · package.json
highInstall Lifecycle Suppresses Failurepostinstall="test -d .git && git config core.hooksPath .githooks || true" · package.json
mediumNew Account With Lifecycle Hookpackage first published 32 day(s) ago, 5 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.7Review72026-06-12
0.1.8Review72026-06-12
0.1.3High risk652026-06-12
0.1.6Review72026-06-01
0.1.4Review72026-05-29
0.1.5Review72026-05-29

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @persona/relay (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @persona/[email protected]