PkgRadar

npm · registry.npmjs.org

@vaadin/bundles

Large Javascript Payload: 12175405 bytes

Why PkgRadar flagged 24.10.3

SeveritySignalEvidence
mediumLarge Javascript Payload12175405 bytes · package/vaadin.js

Scanned versions

VersionVerdictScoreScanned (UTC)
25.2.0-beta2Low risk02026-06-09
24.10.4Low risk02026-06-09
24.9.16Low risk02026-06-09
25.1.4Low risk02026-06-08
25.0.13Low risk02026-06-08
24.10.3Review102026-05-25
25.2.0-beta1Review102026-05-25

Block this in CI

PkgRadar gates @vaadin/bundles (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @vaadin/[email protected]