<p align="center"> <img src="https://img.shields.io/badge/python-3.11%2B-3776AB?style=flat-square&logo=python&logoColor=white" alt="Python 3.11+"> <img src="https://img.shields.io/badge/license-GPL--3.0-491?style=flat-square" alt="License: GPL-3.0">
The postinstall hook can modify the installing project's package.json by approving lifecycle scripts for installed dependencies. This weakens the consumer's script approval gate without an explicit user command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
scripts/lib/extension-debug-harness.tsView on unpkg · L137Package ships non-JavaScript build or shell helper files.
scripts/pi-usereq-debug.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/core/pi-notify.tsView on unpkgThis report applies to pi-usereq@0.60.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L27Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L27Package ships non-JavaScript build or shell helper files.
scripts/pi-usereq-debug.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/core/pi-notify.tsView on unpkgPackage source references dynamic require/import behavior.
scripts/lib/extension-debug-harness.tsView on unpkg · L137