Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@okki-aireach/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@okki-aireach/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Payload: matched "cUrl "
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 12 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/dist/index.js | matched "cUrl " | 12 |
Manifest
Package metadata
Scripts19
buildtsc -bbuild:allbun run sync:crm-exported-tooling && bun run build && bun run test:go && bun run build:go && bun run build:go:matrix && bun run bundle:single-file && bun run bundle:native && bun run bundle:native:matrix && bun run prepare:platform-packagesbuild:gomkdir -p dist && go build -o ./dist/aireach-cli-go .build:go:linux-arm64mkdir -p dist && GOOS=linux GOARCH=arm64 CGO_ENABLED=0 go build -o ./dist/aireach-cli-go-linux-arm64 .build:go:linux-x64mkdir -p dist && GOOS=linux GOARCH=amd64 CGO_ENABLED=0 go build -o ./dist/aireach-cli-go-linux-x64 .build:go:matrixnode ./scripts/build-go-matrix.mjsbuild:npmbun run embed:scenes && bun run buildbuild:platformsbun run test:go && bun run build:go:matrix && bun run prepare:platform-packagesbuild:publishbun run build:npm && bun run build:platformsbundle:nativemkdir -p dist && bun build --compile ./src/index.ts --outfile ./dist/aireach-cli.nativebundle:native:matrixnode ./scripts/build-native-matrix.mjsbundle:releasenode ./scripts/build-release.mjsbundle:single-filemkdir -p dist && bun build ./src/index.ts --target=node --outfile ./dist/aireach-cli.single.js && chmod +x ./dist/aireach-cli.single.jsembed:scenesnode ./scripts/embed-scenes.mjsprepackbun run build:npmprepare:platform-packagesnode ./scripts/prepare-platform-packages.mjssync:crm-exported-toolingnode ./scripts/sync-crm-exported-tooling.mjstest:gogo test ./...typechecktsc -b --pretty false
Optional dependencies6
@okki-aireach/aireach-cli-darwin-arm640.1.2@okki-aireach/aireach-cli-darwin-x640.1.2@okki-aireach/aireach-cli-linux-arm640.1.2@okki-aireach/aireach-cli-linux-x640.1.2@okki-aireach/aireach-cli-windows-ia320.1.2@okki-aireach/aireach-cli-windows-x640.1.2