PkgRadar

npm · registry.npmjs.org

@things-factory/operato-codelingua

Remote Payload: matched "curl "

Why PkgRadar flagged 8.0.20

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/installer/install.sh
mediumRemote Payloadmatched "curl " · package/installer/upgrade.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
8.0.20Review122026-06-11
9.2.27Low risk02026-06-11
9.2.25Low risk02026-06-08
10.0.0-beta.97Low risk02026-06-03
10.0.0-beta.96Low risk02026-05-31
10.0.0-beta.95Low risk02026-05-30
10.0.0-beta.94Low risk02026-05-28
10.0.0-beta.93Low risk02026-05-26
10.0.0-beta.92Low risk02026-05-26
10.0.0-beta.91Low risk02026-05-26
10.0.0-beta.89Low risk02026-05-24
10.0.0-beta.90Low risk02026-05-24

Block this in CI

PkgRadar gates @things-factory/operato-codelingua (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @things-factory/[email protected]