PkgRadar

npm · registry.npmjs.org

just-bash-nx

Remote Payload: matched "curl "

Why PkgRadar flagged 3.0.8

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/bundle/index.cjs
mediumRemote Payloadmatched "curl " · package/dist/bundle/browser.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.15Low risk02026-06-17
3.0.14Low risk02026-06-17
3.0.13Low risk02026-06-16
3.0.12Low risk02026-06-16
3.0.11Low risk02026-06-15
3.0.10Low risk02026-06-14
3.0.7Low risk02026-06-14
3.0.8Review242026-05-26
3.0.9Review242026-05-26

Block this in CI

PkgRadar gates just-bash-nx (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]