PkgRadar

npm · registry.npmjs.org

orquesta-cli

Install-time lifecycle script: preinstall="node scripts/check-node.cjs"

Why PkgRadar flagged 0.2.13

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspreinstall added in 0.2.13 vs 0.2.12: "node scripts/check-node.cjs" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.38Review32026-06-04
0.2.37Review32026-06-04
0.2.36Review32026-06-04
0.2.35Review32026-06-04
0.2.13High risk452026-06-03
0.2.34Review32026-06-02
0.2.33Review52026-06-02
0.2.25Review52026-06-01
0.2.23Review52026-06-01
0.2.24Review32026-06-01
0.2.22Review32026-05-31
0.2.21Review32026-05-31
0.2.20Review32026-05-31
0.2.19Review52026-05-31
0.2.18Review32026-05-31
0.2.17Review32026-05-30
0.2.16Review32026-05-30
0.2.14Review52026-05-30
0.2.15Review52026-05-30
0.2.11Low risk02026-05-28
0.2.12Low risk02026-05-28
0.2.5Low risk02026-05-28
0.2.4Low risk02026-05-28
0.2.1Low risk02026-05-27
0.2.2Low risk02026-05-27
0.1.27Review122026-05-24
0.2.0Review122026-05-24

Related campaigns

Block this in CI

PkgRadar gates orquesta-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]