PkgRadar

npm · registry.npmjs.org

@loicngr/kobo

Large Javascript Payload: 2537640 bytes

Why PkgRadar flagged 1.7.19

SeveritySignalEvidence
mediumLarge Javascript Payload2537640 bytes · package/src/client/dist/spa/assets/editor.api-B85Aec2m.js
mediumLarge Javascript Payload5937330 bytes · package/src/client/dist/spa/assets/ts.worker-Cj3zTgVE.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.8.0Low risk02026-06-12
1.7.34Low risk02026-06-12
1.7.32Low risk02026-06-12
1.7.31Low risk02026-06-10
1.7.30Low risk02026-06-08
1.7.29Low risk02026-06-05
1.7.28Low risk02026-06-04
1.7.27Low risk02026-06-04
1.7.26Low risk02026-06-03
1.7.25Low risk02026-06-02
1.7.24Low risk02026-05-30
1.7.23Low risk02026-05-30
1.7.22Low risk02026-05-29
1.7.21Low risk02026-05-29
1.7.19Review72026-05-25
1.7.20Review72026-05-25

Block this in CI

PkgRadar gates @loicngr/kobo (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @loicngr/[email protected]