PkgRadar

npm · registry.npmjs.org

electron-manager

Remote Payload: matched "github.com/actions/runner/releases/download"

Why PkgRadar flagged 1.8.5

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/actions/runner/releases/download" · package/dist/commands/runner.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.8.5Review52026-06-17
1.8.4Review52026-06-17
1.8.3Review52026-06-17
1.8.2Review52026-06-17
1.8.1Review52026-06-16
1.7.1Review52026-06-11
1.7.0Review52026-06-11
1.6.1Review52026-06-11
1.5.2Review52026-06-10
1.4.3Review52026-06-10
1.5.1Review52026-06-10
1.5.0Review52026-06-02
1.4.4Review52026-06-02

Block this in CI

PkgRadar gates electron-manager (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]