PkgRadar

npm · registry.npmjs.org

cielara

Install-time lifecycle script: postinstall="node scripts/postinstall.js"

Why PkgRadar flagged 0.1.20

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.1.20 vs 0.0.1: "node scripts/postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.20High risk452026-06-10
0.1.34Review12026-06-05
0.1.33Review12026-06-05
0.1.32Review12026-06-05
0.1.31Review12026-06-05
0.1.30Review12026-06-05
0.1.29Review12026-06-05
0.1.28Review12026-06-05
0.1.27Review12026-06-04
0.1.25Review12026-06-03
0.1.24Review12026-06-03
0.1.22Review12026-06-01
0.1.23Review12026-06-01
0.1.21Review12026-06-01
0.0.1Low risk02026-05-30

Block this in CI

PkgRadar gates cielara (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]