PkgRadar

npm · registry.npmjs.org

gramene-search

Remote Payload: matched "curl "

Why PkgRadar flagged 2.1.10

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/.claude/settings.local.json
mediumLarge Javascript Payload19128141 bytes · package/src/static/jbrowse2.umd.dev.js
mediumLarge Javascript Payload8721207 bytes · package/sorghum/sorghum.4d3065de.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.6.0Low risk02026-06-08
2.5.3Low risk02026-06-06
2.5.2Low risk02026-06-05
2.5.1Low risk02026-06-05
2.5.0Low risk02026-06-05
2.4.0Low risk02026-06-05
2.3.0Low risk02026-06-04
2.2.0Low risk02026-06-02
2.1.11Low risk02026-05-28
2.1.10Review92026-05-27

Block this in CI

PkgRadar gates gramene-search (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]
gramene-search — npm security scan | PkgRadar