PkgRadar

npm · registry.npmjs.org

passbolt-styleguide

Remote Payload: matched "curl "

Why PkgRadar flagged 5.14.0-alpha.2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/ci-scripts/bin/slack-status-messages.sh
mediumRemote Dependency Specdependencies.react-list="github:passbolt/react-list#v0.8.18" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
5.14.0-alpha.2Review72026-06-12
5.13.0Review72026-06-09
5.13.0-alpha.8Review72026-06-05
5.13.0-alpha.7Review72026-06-04
5.13.0-alpha.6Review72026-05-29
5.13.0-alpha.5Review72026-05-28
5.13.0-alpha.3Review242026-05-27
5.13.0-alpha.0Review242026-05-27
5.13.0-alpha.2Review242026-05-27

Block this in CI

PkgRadar gates passbolt-styleguide (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]