PkgRadar

npm · registry.npmjs.org

sigillum-js

Install Lifecycle Suppresses Failure: postinstall="test -d patches && patch-package || true"

Why PkgRadar flagged 1.5.3

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="test -d patches && patch-package || true" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.3Review72026-06-08
2.0.0-beta.9Review72026-06-08
2.0.0-beta.8Review72026-05-31
2.0.0-beta.7Review72026-05-31
1.5.2Review72026-05-31

Block this in CI

PkgRadar gates sigillum-js (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]