PkgRadar

npm · registry.npmjs.org

specweave

Install Lifecycle Suppresses Failure: preinstall="node scripts/check-node-version.js || exit 0"

Why PkgRadar flagged 1.0.592

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepreinstall="node scripts/check-node-version.js || exit 0" · package.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/src/core/fabric/discovery/content-fetcher.js
mediumRemote Payloadmatched "api.github.com/graphql" · package/dist/src/sync/projects-v2.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/src/cli/commands/update.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.592High risk492026-06-17
1.0.591High risk492026-06-10
1.0.590High risk492026-06-10
1.0.589High risk492026-06-10
1.0.588High risk492026-06-10
1.0.587High risk492026-06-10
1.0.585High risk492026-06-10
1.0.586High risk492026-06-10

Block this in CI

PkgRadar gates specweave (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]