PkgRadar

npm · registry.npmjs.org

@pine-ds/core

Install Lifecycle Suppresses Failure: postinstall="node ./dist/scripts/vscode-settings-patcher.cjs || true"

Why PkgRadar flagged 3.26.4

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="node ./dist/scripts/vscode-settings-patcher.cjs || true" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
3.26.4High risk122026-06-10
3.26.3High risk122026-06-10
3.26.1High risk122026-06-10

Block this in CI

PkgRadar gates @pine-ds/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @pine-ds/[email protected]