PkgRadar

npm · registry.npmjs.org

electron-cli

Install-time lifecycle script: postinstall="node scripts/install.js"

Why PkgRadar flagged 0.3.0-alpha.1

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.3.0-alpha.1 vs 0.3.0-alpha.0: "node scripts/install.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0-alpha.1High risk452026-06-03
0.3.0-alpha.20Review12026-05-31
0.3.0-alpha.19Review12026-05-31
0.3.0-alpha.18Review12026-05-31
0.3.0-alpha.17Review12026-05-31
0.3.0-alpha.16Review12026-05-31
0.3.0-alpha.15Review12026-05-31
0.3.0-alpha.14Review12026-05-31
0.3.0-alpha.13Review12026-05-31
0.3.0-alpha.12Review12026-05-31
0.3.0-alpha.11Review12026-05-31
0.3.0-alpha.10Review12026-05-31
0.3.0-alpha.9Review12026-05-30
0.3.0-alpha.8Review12026-05-30
0.3.0-alpha.7Review12026-05-30
0.3.0-alpha.6Review12026-05-30
0.3.0-alpha.5Review12026-05-30
0.3.0-alpha.4Review12026-05-30
0.3.0-alpha.3Review12026-05-30
0.3.0-alpha.2Review12026-05-30
0.3.0-alpha.0Low risk02026-05-30
0.2.8Low risk02026-05-30

Block this in CI

PkgRadar gates electron-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]