PkgRadar

npm · registry.npmjs.org

@smg-automotive/components

Install-time lifecycle script: postinstall="npm run typegen"

Why PkgRadar flagged 25.29.0-chakra-v3.1

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 25.29.0-chakra-v3.1 vs 25.28.1-ui-dependencies.1: "npm run typegen" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
25.29.0-chakra-v3.1High risk452026-06-13
25.29.1-ui-dependencies.1Low risk02026-06-11
25.28.0-box-as-fix.1High risk452026-06-10
25.30.0-chakra-v3.1High risk452026-06-10
25.29.0Low risk02026-06-08
25.29.0-talamcol-message-sparkle.1Low risk02026-06-08
25.28.1-ui-dependencies.1Low risk02026-05-28
25.28.0-chakra-v3.4Review22026-05-28
25.28.0-box-as-fix.2Review22026-05-28
25.28.0Low risk02026-05-28
25.28.0-chakra-v3.2Review22026-05-26
25.27.0-ST-1872-optimizer-navigation-link.8Low risk02026-05-25
25.27.0-ST-1872-optimizer-navigation-link.9Low risk02026-05-25

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @smg-automotive/components (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @smg-automotive/[email protected]