PkgRadar

npm · registry.npmjs.org

synapse-orch-ai

Remote Payload: matched "github.com/FiloSottile/mkcert/releases/download"

Why PkgRadar flagged 1.7.6

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/FiloSottile/mkcert/releases/download" · package/frontend-build/node_modules/next/dist/lib/mkcert.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.7.6Review472026-06-11
1.7.5Review472026-06-11
1.7.3Review472026-06-10
1.7.2Review472026-06-10
1.7.1Review472026-06-08
1.7.0Review472026-06-05
1.6.6Review592026-05-27
1.6.5Review592026-05-25
1.6.4Review1842026-05-24
1.6.3Review1842026-05-24
1.6.1Review1842026-05-24
1.6.2Review1842026-05-24

Block this in CI

PkgRadar gates synapse-orch-ai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]