PkgRadar

npm · registry.npmjs.org

@tankpkg/cli

Remote Payload: matched "github.com/tankpkg/tank/releases/download"

Why PkgRadar flagged 0.0.0-nightly.20260609.9f69485

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/tankpkg/tank/releases/download" · package/dist/bin/tank.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.0-nightly.20260609.9f69485Review32026-06-09
0.0.0-nightly.20260608.9f69485Review32026-06-08
0.0.0-nightly.20260607.9f69485Review32026-06-07
0.0.0-nightly.20260606.9f69485Review32026-06-06
0.0.0-nightly.20260605.9f69485Review32026-06-05
0.0.0-nightly.20260604.9f69485Review32026-06-04
0.0.0-nightly.20260603.9f69485Review32026-06-03
0.0.0-nightly.20260602.9f69485Review32026-06-02
0.0.0-nightly.20260601.9f69485Review32026-06-01
0.0.0-nightly.20260531.9f69485Review32026-05-31
0.0.0-nightly.20260530.9f69485Review32026-05-30
0.0.0-nightly.20260529.9f69485Review32026-05-29
0.0.0-nightly.20260528.9f69485Review32026-05-28
0.0.0-nightly.20260527.9f69485Review32026-05-27
0.0.0-nightly.20260526.9f69485Review32026-05-26
0.0.0-nightly.20260525.6157499Low risk02026-05-25
0.16.2Review122026-05-24
0.0.0-nightly.20260524.6157499Review122026-05-24

Block this in CI

PkgRadar gates @tankpkg/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @tankpkg/[email protected]