PkgRadar

npm · registry.npmjs.org

@promus/cli

Remote Payload: matched "api.telegram.org/bot"

Why PkgRadar flagged 0.24.30

SeveritySignalEvidence
mediumRemote Payloadmatched "api.telegram.org/bot" · package/src/util/telegram-secrets.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.24.30Review222026-06-14
0.24.29Review222026-06-14
0.24.28Review222026-06-14
0.24.26Review222026-06-14
0.24.27Review222026-06-14
0.24.24Review222026-06-14
0.24.25Review222026-06-14
0.24.23Review222026-06-13
0.24.22Review222026-06-13
0.24.21Review222026-06-13
0.24.20Review222026-06-13
0.24.19Review222026-06-13
0.24.18Review222026-06-13
0.24.17Review222026-06-13

Block this in CI

PkgRadar gates @promus/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @promus/[email protected]