PkgRadar

npm · registry.npmjs.org

tower-studio

Remote Payload: matched "github.com/FiloSottile/mkcert/releases/download"

Why PkgRadar flagged 0.2.39

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/FiloSottile/mkcert/releases/download" · package/.next/standalone/node_modules/next/dist/lib/mkcert.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.39Review172026-06-17
0.2.38Review172026-06-16
0.2.37Review172026-06-16
0.2.36Review112026-06-16
0.2.35Review112026-06-16
0.2.34Review112026-06-16
0.2.33Review112026-06-12
0.2.32Review112026-06-12
0.2.31Review112026-06-12
0.2.30Review112026-06-12
0.2.29Review112026-06-11
0.2.28Review172026-06-11
0.2.27Review172026-06-11
0.2.26Review172026-06-11
0.2.25Review172026-06-11
0.2.24Review112026-06-11
0.2.23Review172026-06-11
0.2.22Review112026-06-11
0.2.21Review112026-06-11
0.2.20Review112026-06-10
0.2.19Review112026-06-10
0.2.18Review112026-05-30
0.2.15Review152026-05-30
0.2.16Review112026-05-30
0.2.14Review112026-05-30
0.2.12Review112026-05-30

Block this in CI

PkgRadar gates tower-studio (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]