PkgRadar

npm · registry.npmjs.org

@pipeline-builder/pipeline-manager

Remote Payload: matched "curl "

Why PkgRadar flagged 3.4.92

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/agent/tools.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.4.92Review222026-06-13
3.4.91Review222026-06-12
3.4.90Review152026-06-11
3.4.89Review152026-06-11
3.4.88Review222026-06-11
3.4.87Review222026-06-11
3.4.86Review152026-06-11
3.4.85Review152026-06-11
3.4.84Review152026-06-11
3.4.83Review222026-06-10
3.4.82Review222026-06-10
3.4.81Review222026-06-10
3.4.80Review222026-06-10
3.4.79Review222026-06-10
3.4.78Review222026-06-10
3.4.77Review222026-06-10
3.4.76Review222026-06-10
3.4.75Review102026-06-10
3.4.74Review72026-06-10
3.4.73Review52026-06-10
3.4.72Review52026-06-10
3.4.71Review32026-06-10
3.4.70Low risk02026-06-08
3.4.69Low risk02026-06-08
3.4.68Low risk02026-06-08
3.4.67Low risk02026-06-07
3.4.66Low risk02026-06-05
3.4.65Low risk02026-06-03
3.4.64Low risk02026-06-02
3.4.63Low risk02026-06-02
3.4.62Low risk02026-06-02
3.4.61Low risk02026-06-01
3.4.60Low risk02026-06-01
3.4.59Low risk02026-06-01
3.4.58Low risk02026-05-30
3.4.57Low risk02026-05-29
3.4.56Low risk02026-05-29
3.4.42Review502026-05-24
3.4.41Review502026-05-24
3.4.40Review502026-05-24
3.4.38Review502026-05-24
3.4.39Review502026-05-24

Block this in CI

PkgRadar gates @pipeline-builder/pipeline-manager (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @pipeline-builder/[email protected]