PkgRadar

npm · registry.npmjs.org

@utoo/pack

Remote Payload: matched "github.com/FiloSottile/mkcert/releases/download"

Why PkgRadar flagged 1.4.13

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/FiloSottile/mkcert/releases/download" · package/cjs/utils/mkcert.js
mediumRemote Payloadmatched "github.com/FiloSottile/mkcert/releases/download" · package/esm/utils/mkcert.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.13Review72026-06-11
1.4.13-alpha.2Review72026-06-10
1.4.13-alpha.1Review72026-06-10
1.4.13-alpha.0Review72026-06-08
1.4.12Review72026-06-05
1.4.12-alpha.10Review72026-06-05
1.4.12-alpha.8Review72026-06-05
1.4.12-alpha.7Review72026-06-05
1.4.12-alpha.6Review72026-06-04
1.4.12-alpha.5Review72026-06-04
1.4.12-alpha.4Review72026-06-04
1.4.12-alpha.2Review72026-06-04
1.4.12-alpha.1Review72026-06-04
1.4.12-alpha.0Review72026-06-03
1.4.10-alpha.0Review72026-06-02
1.4.11Review72026-06-02
1.4.9-alpha.0Review72026-06-02
1.4.8Review72026-05-26
1.4.9Review72026-05-26

Block this in CI

PkgRadar gates @utoo/pack (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @utoo/[email protected]