PkgRadar

npm · registry.npmjs.org

@fedify/vocab

Large Javascript Payload: 2556825 bytes

Why PkgRadar flagged 2.3.0-dev.1184

SeveritySignalEvidence
mediumLarge Javascript Payload2556825 bytes · package/dist/mod.cjs
mediumLarge Javascript Payload2481508 bytes · package/dist/mod.js
mediumLarge Javascript Payload2466667 bytes · package/dist-tests/vocab-B0Z-tH4q.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.3.0-dev.1299Low risk02026-06-11
2.3.0-dev.1281Low risk02026-06-10
2.3.0-dev.1280Low risk02026-06-10
2.3.0-dev.1274Low risk02026-06-09
2.3.0-dev.1273Low risk02026-06-09
2.3.0-dev.1258Low risk02026-06-07
2.3.0-dev.1219Low risk02026-06-05
2.2.5Low risk02026-06-05
2.1.16Low risk02026-06-05
2.0.20Low risk02026-06-05
2.3.0-dev.1214Low risk02026-06-05
2.3.0-dev.1213Low risk02026-06-04
2.3.0-dev.1212Low risk02026-06-04
2.2.4Low risk02026-06-04
2.1.15Low risk02026-06-04
2.0.19Low risk02026-06-04
2.3.0-dev.1190Low risk02026-06-01
2.3.0-dev.1189Low risk02026-06-01
2.3.0-dev.1184Review92026-05-28
2.3.0-dev.1158Review92026-05-25
2.3.0-dev.1172Review92026-05-25

Block this in CI

PkgRadar gates @fedify/vocab (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @fedify/[email protected]