Loading npm security reports…
Validation-first deployment: fork a warm running instance, verify, promote via atomic proxy flip, roll back by pointer.
Postinstall fetches an opaque native binary from GitHub Releases, extracts it into bin/, and marks it executable. The wrapper later runs that uninspectable binary.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L23Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L23