Loading npm security reports…
Validation-first deployment: fork a warm running instance, verify, promote via atomic proxy flip, roll back by pointer.
Postinstall retrieves an unverified executable payload from GitHub Releases and stores it in the package bin directory. The CLI shim executes that payload when the user runs hotlane.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L23Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L23