PkgRadar

npm · registry.npmjs.org

yz-gallery-deploy

Remote Payload: matched "curl "

Why PkgRadar flagged 1.3.19

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/commands/config.js
mediumRemote Payloadmatched "curl " · package/dist/commands/deploy.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.19Review242026-06-11
1.3.17Review242026-06-09
1.3.15Review242026-06-08
1.3.14Review242026-06-07
1.3.13Review242026-06-07
1.3.12Review242026-06-07
1.3.11Review242026-06-06
1.3.10Review242026-06-06
1.3.9Review242026-06-06
1.3.8Review242026-06-06
1.3.7Review242026-06-06
1.3.6Review242026-06-06
1.3.3Review242026-06-05
1.2.14Review242026-05-27
1.2.13Review242026-05-27

Block this in CI

PkgRadar gates yz-gallery-deploy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]