PkgRadar

npm · registry.npmjs.org

@heymantle/litho

Large Javascript Payload: 2954065 bytes

Why PkgRadar flagged 0.0.19

SeveritySignalEvidence
mediumLarge Javascript Payload2954065 bytes · package/dist/cjs/storybook-static/sb-manager/globals-runtime.js
mediumLarge Javascript Payload2954051 bytes · package/dist/esm/storybook-static/sb-manager/globals-runtime.js
mediumLarge Javascript Payload2688571 bytes · package/dist/cjs/storybook-static/assets/iframe-0Hqid0v8.js
mediumLarge Javascript Payload2674841 bytes · package/dist/esm/storybook-static/assets/iframe-0Hqid0v8.js
mediumLarge Javascript Payload2688571 bytes · package/dist/cjs/storybook-static/assets/iframe-835uJm5r.js
mediumLarge Javascript Payload2674841 bytes · package/dist/esm/storybook-static/assets/iframe-835uJm5r.js
mediumLarge Javascript Payload2689834 bytes · package/dist/cjs/storybook-static/assets/iframe-CFdo3VNg.js
mediumLarge Javascript Payload2676104 bytes · package/dist/esm/storybook-static/assets/iframe-CFdo3VNg.js
mediumLarge Javascript Payload2690531 bytes · package/dist/cjs/storybook-static/assets/iframe-Dh334ofi.js
mediumLarge Javascript Payload2676621 bytes · package/dist/esm/storybook-static/assets/iframe-Dh334ofi.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.20Low risk02026-05-28
0.0.19Review702026-05-27
0.0.18Review422026-05-25
0.0.16Low risk02026-05-25
0.0.17Review422026-05-25

Block this in CI

PkgRadar gates @heymantle/litho (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @heymantle/[email protected]