PkgRadar

npm · registry.npmjs.org

@whatwg-node/node-fetch

Remote Payload: matched "curl "

Why PkgRadar flagged 0.8.6-alpha-20260522183702-aa18fd81fea1e58da4ec53ce02d6797bedb44001

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/cjs/fetch.js
mediumRemote Payloadmatched "Curl " · package/esm/fetch.js
mediumRemote Payloadmatched "Curl " · package/cjs/fetchCurl.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.6-alpha-20260602131357-6b87fb6ad89caf324b898904f95dd377f51c1331Low risk02026-06-02
0.8.6Low risk02026-06-02
0.8.6-alpha-20260602071518-7f286a12cb5f1b26688461863846094c3b2f951cLow risk02026-06-02
0.8.6-alpha-20260602003113-42303a31d4dae055b0b8489fcbbad2db2ebfbe14Low risk02026-06-02
0.8.6-alpha-20260601161459-b48f5e66d604a855249bf4b01a074abd0699f2c3Low risk02026-06-01
0.8.6-alpha-20260601161904-05f344aaf80bd89e9e8ffbe8e554a6798132f863Low risk02026-06-01
0.8.6-alpha-20260531220009-7a6a5c7786a4d330bee80d623fa208343112cd30Low risk02026-05-31
0.8.6-alpha-20260530175958-13c230f5073521c998015e0d5665fde48afe6d1eLow risk02026-05-30
0.8.6-alpha-20260529213145-5d8982b95686b0b2e97524eadd2582fcf948b978Low risk02026-05-29
0.8.6-alpha-20260528214104-a71e055b9ac56c041fea958b52643ed705326666Low risk02026-05-29
0.8.6-alpha-20260528133443-bab88ff81271e43ba1d2c0255642097232b8c6d5Low risk02026-05-28
0.8.6-alpha-20260525224515-9f4945eda30db91646df29ba00a48741a4404534Low risk02026-05-25
0.8.6-alpha-20260525175947-83d0d8ba12f399db90c5ead74e30022642080067Low risk02026-05-25
0.8.6-alpha-20260522183702-aa18fd81fea1e58da4ec53ce02d6797bedb44001Review362026-05-25
0.8.6-alpha-20260525010154-0317c1ca5132629d5d08d9bbcf95163dafaeeeafReview362026-05-25

Block this in CI

PkgRadar gates @whatwg-node/node-fetch (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @whatwg-node/node-fetch@0.8.6-alpha-20260522183702-aa18fd81fea1e58da4ec53ce02d6797bedb44001