PkgRadar

npm · registry.npmjs.org

@seanyao/roll

Remote Payload: matched "curl "

Why PkgRadar flagged 3.613.2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/lib/i18n/skills/roll-build.sh
mediumRemote Payloadmatched "curl " · package/lib/i18n/update.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
3.613.2Review162026-06-13
3.613.1Review162026-06-13
3.612.1Review162026-06-12
3.611.3Review242026-06-11
3.610.2Review242026-06-11
3.611.2Review242026-06-11
3.610.1Review162026-06-10
3.609.2Review242026-06-09
3.608.1Review162026-06-07
3.607.2Review162026-06-07
3.607.1Review162026-06-06
3.606.3Review162026-06-06
3.606.2Review242026-06-05
3.606.1Review242026-06-05
3.0.0Review162026-06-05
2.604.2Review162026-06-04
2.604.1Review162026-06-03
2.603.1Review242026-06-03
2.602.5Review162026-06-02
2.602.4Review162026-06-02
2.602.3Review162026-06-02
2.602.2Review242026-06-02
2.602.1Review242026-06-02
2026.601.4Review82026-06-01
2026.601.3Review82026-06-01
2026.601.2Review82026-06-01
2026.601.1Review82026-06-01
2026.529.5Review82026-05-29
2026.529.4Review122026-05-29
2026.529.3Review122026-05-29
2026.529.2Review82026-05-29
2026.529.1Review82026-05-28
2026.528.2Review122026-05-28
2026.527.1Review82026-05-27
2026.526.1Review122026-05-26
2026.525.1Review122026-05-25
2026.524.2Review122026-05-24
2026.524.1Review122026-05-24
2026.523.2Low risk02026-05-24

Block this in CI

PkgRadar gates @seanyao/roll (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @seanyao/[email protected]