PkgRadar

npm · registry.npmjs.org

@tyroneross/build-loop

Remote Payload: matched "curl "

Why PkgRadar flagged 0.30.3

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/hooks/_session_start_lib.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.30.3Review122026-06-12

Block this in CI

PkgRadar gates @tyroneross/build-loop (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @tyroneross/[email protected]