PkgRadar

npm · registry.npmjs.org

cdk-common

Remote Payload: matched "curl "

Why PkgRadar flagged 2.1.58

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/node_modules/@aws-cdk/cfnspec/build-tools/update-cfnlint.sh
mediumRemote Payloadmatched "curl " · package/node_modules/@aws-cdk/cfnspec/build-tools/update.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.58Review72026-06-17
2.1.57Review72026-06-16
2.1.56Review72026-06-14
2.1.55Review102026-05-27
2.1.54Review102026-05-26
2.1.52Review1722026-05-25
2.1.53Review1722026-05-25

Block this in CI

PkgRadar gates cdk-common (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]