Binary wrapper for Hugo
An automatic install hook removes a consumer-project directory unrelated to the package's own destination. It then obtains and runs a binary from a configurable repository.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package automatically runs its installer after installation.
package.jsonView on unpkg · L67Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe installer targets the consumer working directory and recursively removes its vendor directory before running the binary setup.
lib/install.jsView on unpkg · L9Download repository selection accepts environment or project configuration, then constructs a release URL from that value.
lib/index.jsView on unpkg · L102Download repository selection accepts environment or project configuration, then constructs a release URL from that value.
lib/index.jsView on unpkg · L146This report applies to hugo-bin@0.165.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L69Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L69The package automatically runs its installer after installation.
package.jsonView on unpkg · L67The installer targets the consumer working directory and recursively removes its vendor directory before running the binary setup.
lib/install.jsView on unpkg · L9Download repository selection accepts environment or project configuration, then constructs a release URL from that value.
lib/index.jsView on unpkg · L102Download repository selection accepts environment or project configuration, then constructs a release URL from that value.
lib/index.jsView on unpkg · L146