PkgRadar

npm · registry.npmjs.org

@vc-shell/create-vc-app

Large Javascript Payload: 3010104 bytes

Why PkgRadar flagged 2.0.6-pr230.6c46c06

SeveritySignalEvidence
mediumLarge Javascript Payload3010104 bytes · package/dist/templates/standalone/_yarn/releases/yarn-4.9.1.cjs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.9Low risk02026-06-11
2.0.8-pr238.047030dLow risk02026-06-11
2.0.8Low risk02026-06-11
2.0.7-pr236.b5ecb25Low risk02026-06-10
2.0.7-pr237.4b187d7Low risk02026-06-10
2.0.7-pr237.2bccbc6Low risk02026-06-10
2.0.7-pr236.cccb3a4Low risk02026-06-10
2.0.7Low risk02026-06-04
2.0.6-pr235.6e1a779Low risk02026-06-04
2.0.6-pr234.df5b1feLow risk02026-06-02
2.0.6-pr234.7f3f395Low risk02026-06-02
2.0.6-pr234.eb6f51dLow risk02026-06-02
2.0.6-pr233.eb3442aLow risk02026-06-02
2.0.6-pr232.5b58c86Low risk02026-06-01
2.0.6-pr230.6c46c06Review52026-05-25
2.0.3-pr229.f4a4c6bReview52026-05-25
2.0.6Review52026-05-25
2.0.4-pr228.1e79eaeReview102026-05-25
2.0.5Review102026-05-25

Block this in CI

PkgRadar gates @vc-shell/create-vc-app (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @vc-shell/[email protected]