PkgRadar

npm · registry.npmjs.org

opencode-dux

Remote Payload: matched "github.com/${REPO}/releases/download"

Why PkgRadar flagged 1.4.12

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/${REPO}/releases/download" · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.12Review122026-06-09
1.4.11Review122026-06-09
1.4.10Review122026-06-05
1.4.8Review122026-06-05
1.4.9Review122026-06-05
1.4.7Review122026-06-05
1.4.6Review122026-06-05
1.4.5Review122026-06-04
1.4.4Review122026-06-04
1.4.2Review122026-06-03
1.4.3Review122026-06-03
1.4.1Review122026-06-02
1.4.0Review122026-06-02
1.3.31Low risk02026-06-02
1.3.29Low risk02026-06-01
1.3.30Low risk02026-06-01
1.3.28Low risk02026-05-25
1.3.27Review482026-05-25
1.3.26Review482026-05-24
1.3.24Review482026-05-24
1.3.25Review482026-05-24

Block this in CI

PkgRadar gates opencode-dux (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]