@firestitch/component-tools
Installing the package mutates the consumer project's editor configuration and Git repository. It can commit and push those changes without user interaction.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package automatically runs postinstall.js during npm installation.
package.jsonView on unpkg · L33Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
webpack.package.jsView on unpkg · L1The install hook deinitializes and removes the consumer's .vscode Git submodule, commits the removal, and pushes it to the configured remote.
postinstall.jsView on unpkg · L15The install hook recursively deletes the consumer project's .vscode directory and replaces it with package-provided files.
postinstall.jsView on unpkg · L22This report applies to @firestitch/component-tools@18.0.18.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L33The package automatically runs postinstall.js during npm installation.
package.jsonView on unpkg · L33Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L33Package source references dynamic require/import behavior.
webpack.package.jsView on unpkg · L1The install hook deinitializes and removes the consumer's .vscode Git submodule, commits the removal, and pushes it to the configured remote.
postinstall.jsView on unpkg · L15The install hook recursively deletes the consumer project's .vscode directory and replaces it with package-provided files.
postinstall.jsView on unpkg · L22