npm · registry.npmjs.org
@sanity/cli
Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.
Why PkgRadar flagged 0.0.0-20260528100500
| Severity | Signal | Evidence |
|---|---|---|
| high | Js Split Join Obfuscation | Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/util/update/isInstalledUsingYarn.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.0.0-20260612111702 | Low risk | 0 | 2026-06-12 |
0.0.0-20260612101602 | Low risk | 0 | 2026-06-12 |
0.0.0-20260612095559 | Low risk | 0 | 2026-06-12 |
0.0.0-20260612092122 | Low risk | 0 | 2026-06-12 |
0.0.0-20260612085324 | Low risk | 0 | 2026-06-12 |
0.0.0-20260612080517 | Low risk | 0 | 2026-06-12 |
0.0.0-20260612074408 | Low risk | 0 | 2026-06-12 |
0.0.0-20260612071721 | Low risk | 0 | 2026-06-12 |
7.2.3 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611125142 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611115619 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611121957 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611113331 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611101421 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611092756 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611085316 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611083958 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611083707 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611083151 | Low risk | 0 | 2026-06-11 |
7.2.2 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611081022 | Low risk | 0 | 2026-06-11 |
0.0.0-20260611075913 | Low risk | 0 | 2026-06-11 |
7.2.1 | Low risk | 0 | 2026-06-10 |
7.2.0 | Low risk | 0 | 2026-06-10 |
0.0.0-20260610123958 | Low risk | 0 | 2026-06-10 |
0.0.0-20260610102421 | Low risk | 0 | 2026-06-10 |
0.0.0-20260610095525 | Low risk | 0 | 2026-06-10 |
0.0.0-20260610094003 | Low risk | 0 | 2026-06-10 |
0.0.0-20260610093829 | Low risk | 0 | 2026-06-10 |
0.0.0-20260610082457 | Low risk | 0 | 2026-06-10 |
0.0.0-20260610082142 | Low risk | 0 | 2026-06-10 |
3.30.2-canary.46 | Low risk | 0 | 2026-06-10 |
7.1.0 | Low risk | 0 | 2026-06-08 |
7.0.1 | Low risk | 0 | 2026-06-04 |
7.0.2 | Low risk | 0 | 2026-06-04 |
7.0.0 | Low risk | 0 | 2026-06-04 |
6.7.2 | Low risk | 0 | 2026-06-03 |
0.0.0-20260603103657 | Low risk | 0 | 2026-06-03 |
6.7.1 | Low risk | 0 | 2026-06-02 |
6.7.0 | Low risk | 0 | 2026-06-02 |
0.0.0-20260528100500 | Review | 12 | 2026-05-28 |
0.0.0-20260527150220 | Low risk | 0 | 2026-05-27 |
0.0.0-20260527151743 | Low risk | 0 | 2026-05-27 |
Block this in CI
pkgradar gate --ecosystem npm @sanity/[email protected]