PkgRadar

npm · registry.npmjs.org

pocketbun

Remote Payload: matched "curl "

Why PkgRadar flagged 0.38.2-pocketbun.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsAuthRefresh-UjveHHwo.js
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsAuthWithOAuth2-DUIE4EoY.js
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsAuthWithOTP-CJKph96j.js
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsAuthWithPassword-DEWj8Jyn.js
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsBatch-DNJl1NTn.js
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsCreate-Be3S3y5K.js
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsDelete-CybOn5jy.js
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsEmailChange-BgOZfOYE.js
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsList-BAfVNUIM.js
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsListAuthMethods-9feSopQX.js
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsPasswordReset-db1tMCuS.js
mediumRemote Payloadmatched "curl " · package/vendor/pocketbase-admin-ui/dist/assets/docsRealtime-PMESvmJN.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.39.4-pocketbun.1Low risk02026-06-15
0.39.4-pocketbun.0Low risk02026-06-15
0.39.3-pocketbun.5Low risk02026-06-12
0.39.3-pocketbun.4Low risk02026-06-12
0.39.3-pocketbun.3Low risk02026-06-12
0.39.3-pocketbun.2Low risk02026-06-12
0.39.3-pocketbun.1Low risk02026-06-12
0.39.3-pocketbun.0Low risk02026-06-12
0.39.2-pocketbun.0Low risk02026-06-08
0.39.1-pocketbun.0Low risk02026-06-04
0.39.0-pocketbun.0Low risk02026-05-29
0.38.2-pocketbun.1Review622026-05-25
0.38.1-pocketbun.2Review502026-05-24
0.38.2-pocketbun.0Review502026-05-24

Block this in CI

PkgRadar gates pocketbun (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]