PkgRadar

npm · registry.npmjs.org

thumbgate

Install Lifecycle Suppresses Failure: postinstall="node bin/postinstall.js || true"

Why PkgRadar flagged 1.27.7

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="node bin/postinstall.js || true" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.27.7High risk282026-06-16
1.25.0High risk192026-06-10
1.23.2High risk282026-06-10
1.23.1High risk192026-06-10
1.23.0High risk192026-06-10
1.27.6High risk282026-06-10
1.27.4High risk192026-06-10
1.27.3High risk192026-06-10
1.27.2High risk192026-06-10
1.26.7High risk192026-06-10
1.26.8High risk192026-06-10
1.26.2High risk192026-06-10
1.26.1High risk192026-06-10
1.26.0High risk192026-06-10
1.25.2High risk282026-06-10
1.25.1High risk192026-06-10

Block this in CI

PkgRadar gates thumbgate (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]