PkgRadar

npm · registry.npmjs.org

@sme.up/ketchup

Large Javascript Payload: 9954680 bytes

Why PkgRadar flagged 12.0.0-SNAPSHOT-20260527091949

SeveritySignalEvidence
mediumLarge Javascript Payload9954680 bytes · package/dist/collection/assets/box-performance.js
mediumLarge Javascript Payload3996722 bytes · package/dist/collection/assets/data-table.js
mediumLarge Javascript Payload3073916 bytes · package/dist/cjs/kup-echart.cjs.entry.js
mediumLarge Javascript Payload3073796 bytes · package/dist/esm/kup-echart.entry.js
mediumLarge Javascript Payload3080759 bytes · package/dist/components/p-19756618.js
mediumLarge Javascript Payload11316716 bytes · package/dist/collection/assets/tree.js

Scanned versions

VersionVerdictScoreScanned (UTC)
12.0.0-SNAPSHOT-20260608074559Low risk02026-06-08
12.0.0-SNAPSHOT-20260608074417Low risk02026-06-08
11.0.5Low risk02026-06-03
12.0.0-SNAPSHOT-20260603074652Low risk02026-06-03
12.0.0-SNAPSHOT-20260527091949Review182026-05-27
12.0.0-SNAPSHOT-20260520134413Review182026-05-26
12.0.0-SNAPSHOT-20260526140509Review182026-05-26

Block this in CI

PkgRadar gates @sme.up/ketchup (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @sme.up/[email protected]