npm · registry.npmjs.org
orchestray
Install Lifecycle Remote Or Exec: postinstall="node -e \"try { require('better-sqlite3') } catch (e) { console.warn('better-sqlite3 not available; FTS5 will be unavailable. Ensure build tools are present or use Node 22.5+'); }\""
Why PkgRadar flagged 2.3.7
| Severity | Signal | Evidence |
|---|---|---|
| high | Install Lifecycle Remote Or Exec | postinstall="node -e \"try { require('better-sqlite3') } catch (e) { console.warn('better-sqlite3 not available; FTS5 will be unavailable. Ensure build tools are present or use Node 22.5+'); }\"" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.3.11 | Low risk | 0 | 2026-06-16 |
2.3.10 | Low risk | 0 | 2026-06-10 |
2.3.9 | Low risk | 0 | 2026-06-10 |
2.3.8 | Low risk | 0 | 2026-06-10 |
2.3.7 | High risk | 35 | 2026-06-10 |
2.3.4 | High risk | 35 | 2026-06-10 |
2.3.5 | Review | 5 | 2026-05-29 |
2.3.6 | Review | 5 | 2026-05-29 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem npm [email protected]