PkgRadar

npm · registry.npmjs.org

@gitlab/duo-cli

Large Javascript Payload: 9127889 bytes

Why PkgRadar flagged 8.98.0

SeveritySignalEvidence
mediumLarge Javascript Payload9127889 bytes · package/dist/index.js
mediumLarge Javascript Payload3444499 bytes · package/dist/sandbox_worker.js

Scanned versions

VersionVerdictScoreScanned (UTC)
8.104.0Low risk02026-06-12
8.103.0Low risk02026-06-10
8.102.0Low risk02026-06-10
8.101.0Low risk02026-06-05
8.100.0Low risk02026-06-04
8.99.0Low risk02026-06-02
8.98.0Review102026-05-25
8.97.0Review202026-05-25
8.97.1Review202026-05-25

Block this in CI

PkgRadar gates @gitlab/duo-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @gitlab/[email protected]