PkgRadar

npm · registry.npmjs.org

generator-living-atlas

Remote Payload: matched "curl "

Why PkgRadar flagged 1.8.21

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/generators/app/templates/deploy-branding.sh
mediumRemote Dependency Specdependencies.onionsay="github:theonion/onionsay" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.8.21Review72026-06-05
1.8.23Review72026-06-05
1.8.19Review72026-06-02
1.8.22Review72026-06-02

Block this in CI

PkgRadar gates generator-living-atlas (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]