Automatic Husky + Gitleaks + SonarQube setup for any JS/TS project
On postinstall, the package mutates the consuming Git project, registers it on a hard-coded HTTP SonarQube server, and configures source scanning. Subsequent injected hooks execute the scanner against all project sources.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L5Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/index.jsView on unpkgPackage source references dynamic require/import behavior.
bin/index.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/gitleaks.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/sonarqube.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/sonarqube.jsView on unpkg · L6Package source invokes a package manager install command at runtime.
lib/husky.jsView on unpkg · L28Package ships non-JavaScript build or shell helper files.
templates/github-template/scripts/run-all-scans.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/packageManager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/github-template/scripts/generate-html.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L21Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L5Package ships non-JavaScript build or shell helper files.
templates/github-template/scripts/run-all-scans.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/packageManager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/github-template/scripts/generate-html.jsView on unpkgPackage source references dynamic require/import behavior.
bin/index.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/gitleaks.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/sonarqube.jsView on unpkg · L6This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/sonarqube.jsView on unpkgPackage source invokes a package manager install command at runtime.
lib/husky.jsView on unpkg · L28