PkgRadar

npm · registry.npmjs.org

@windmill-labs/components

Install Lifecycle Remote Or Exec: postinstall="node -e \"if (require('fs').existsSync('./scripts/untar_ui_builder.js')) { require('child_process').execSync('node ./scripts/untar_ui_builder.js', {stdio: 'inherit'}) }\""

Why PkgRadar flagged 1.706.4

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"if (require('fs').existsSync('./scripts/untar_ui_builder.js')) { require('child_process').execSync('node ./scripts/untar_ui_builder.js', {stdio: 'inherit'}) }\"" · package.json
mediumNew Account With Lifecycle Hookpackage first published 17 day(s) ago, 7 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.706.4High risk452026-06-08
1.706.6High risk452026-06-08
1.706.7High risk452026-06-08
1.719.0High risk452026-06-08

Block this in CI

PkgRadar gates @windmill-labs/components (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @windmill-labs/[email protected]