PkgRadar

npm · registry.npmjs.org

@galacean/cli

Large Javascript Payload: 40334142 bytes

Why PkgRadar flagged 2.0.0-alpha.26

SeveritySignalEvidence
mediumLarge Javascript Payload40334142 bytes · package/dist/cli.bundle.cjs
mediumLarge Javascript Payload5547581 bytes · package/dist/preview-client/_static/index-c3dec278.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.0-alpha.29Low risk02026-06-03
2.0.0-alpha.28Low risk02026-06-03
2.0.0-alpha.27Low risk02026-05-28
2.0.0-alpha.26Review102026-05-28
2.0.0-alpha.25Review102026-05-28
2.0.0-alpha.24Review102026-05-26
2.0.0-alpha.23Review102026-05-26
2.0.0-alpha.22Review202026-05-24
2.0.0-alpha.20Review202026-05-24
2.0.0-alpha.21Review202026-05-24

Block this in CI

PkgRadar gates @galacean/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @galacean/[email protected]