PkgRadar

npm · registry.npmjs.org

@pnp/sp

Remote Payload: matched "cUrl "

Why PkgRadar flagged 4.20.0-v4nightly.20260522

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · package/files/types.js

Scanned versions

VersionVerdictScoreScanned (UTC)
4.20.0-v4nightly.20260610Low risk02026-06-11
1.3.11Low risk02026-06-11
1.3.2-0Low risk02026-06-11
4.20.0Low risk02026-06-11
1.3.10Low risk02026-06-11
4.20.0-v4nightly.20260611Low risk02026-06-11
4.20.0-v4nightly.20260609Low risk02026-06-09
4.20.0-v4nightly.20260608Low risk02026-06-09
4.20.0-v4nightly.20260605Low risk02026-06-05
4.20.0-v4nightly.20260604Low risk02026-06-04
4.20.0-v4nightly.20260603Low risk02026-06-03
4.20.0-v4nightly.20260602Low risk02026-06-02
4.20.0-v4nightly.20260601Low risk02026-06-01
4.20.0-v4nightly.20260529Low risk02026-05-29
4.20.0-v4nightly.20260528Low risk02026-05-28
4.20.0-v4nightly.20260527Low risk02026-05-27
4.20.0-v4nightly.20260526Low risk02026-05-26
4.20.0-v4nightly.20260522Review122026-05-25
4.20.0-v4nightly.20260525Review122026-05-25

Block this in CI

PkgRadar gates @pnp/sp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @pnp/[email protected]