PkgRadar

npm · registry.npmjs.org

@ruvector/postgres-cli

Remote Payload: matched "wget "

Why PkgRadar flagged 0.2.8

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · package/dist/commands/install.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.8Review122026-05-25
0.2.9Review122026-05-25

Block this in CI

PkgRadar gates @ruvector/postgres-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @ruvector/[email protected]