PkgRadar

npm · registry.npmjs.org

hermes-native-bridge

Remote Payload: matched "curl "

Why PkgRadar flagged 0.1.13

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/script/bridge_ctl.sh
mediumRemote Payloadmatched "curl " · package/script/ensure_bridge.sh
mediumRemote Payloadmatched "curl " · package/script/setup_bridge_env.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.13Review362026-06-06
0.1.12Review362026-06-06
0.1.11Review362026-06-04
0.1.8Review362026-06-04
0.1.7Review362026-06-04
0.1.6Review362026-06-03
0.1.5Review362026-06-03
0.1.3Review362026-06-03
0.1.4Review362026-06-03
0.1.0Review362026-06-03

Block this in CI

PkgRadar gates hermes-native-bridge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]