PkgRadar

npm · registry.npmjs.org

color-name-list

Remote Payload: matched "curl "

Why PkgRadar flagged 14.37.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/package.json
mediumRemote Payloadmatched "curl " · package/scripts/tools/getImageColors.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
14.40.0Low risk02026-05-30
14.39.0Low risk02026-05-28
14.39.1Low risk02026-05-28
14.37.0Review82026-05-26
14.38.0Review82026-05-26

Block this in CI

PkgRadar gates color-name-list (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]