PkgRadar

npm · registry.npmjs.org

@yancyyu/openhermit

Install-time lifecycle script: postinstall="node ./bin/postinstall.mjs"

Why PkgRadar flagged 1.6.14

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 1.6.14 vs 1.6.13: "node ./bin/postinstall.mjs" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.14High risk452026-06-10
1.6.41Review32026-06-07
1.6.40Review32026-06-07
1.6.39Review32026-06-07
1.6.38Review22026-06-02
1.6.36Review22026-06-01
1.6.37Review22026-06-01
1.6.35Review22026-05-30
1.6.34Review22026-05-30
1.6.33Review22026-05-30
1.6.32Review52026-05-30
1.6.31Review22026-05-30
1.6.30Review22026-05-29
1.6.29Review192026-05-27
1.6.28Review272026-05-26
1.6.27Review272026-05-26
1.6.26Review272026-05-26
1.6.25Review272026-05-26
1.6.24Review272026-05-26
1.6.23Review272026-05-26
1.6.20Review272026-05-26
1.6.19Review272026-05-26
1.6.18Review272026-05-26
1.6.17Review272026-05-26
1.6.16Review272026-05-26
1.6.15Review272026-05-26
1.6.12Review232026-05-25
1.6.13Review232026-05-25
1.6.8Review462026-05-25
1.6.9Review462026-05-25
1.6.4Review442026-05-25
1.6.3Review602026-05-25
1.6.2Review602026-05-25
1.6.1Review602026-05-25
1.5.13Review602026-05-24
1.5.11Review602026-05-24
1.5.10Review602026-05-24
1.5.8Review602026-05-24
1.5.9Review602026-05-24

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @yancyyu/openhermit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @yancyyu/[email protected]