PkgRadar

npm · registry.npmjs.org

@vellumai/web

Credential file access: matched ".ssh/"

Why PkgRadar flagged 0.8.6

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.8.6 vs 0.0.1: "bun run scripts/postinstall.ts" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.12-dev.202606131340.9c0531aReview22026-06-13
0.8.12-dev.202606131247.4d64b75Review22026-06-13
0.8.12-dev.202606131055.4d64b75Review22026-06-13
0.8.12-dev.202606131142.4d64b75Review22026-06-13
0.8.12-dev.202606130730.4d64b75Review52026-06-13
0.8.12-dev.202606130914.4d64b75Review52026-06-13
0.8.12-dev.202606130540.3758c47Review22026-06-13
0.8.12-dev.202606130318.6b9805dReview22026-06-13
0.8.12-dev.202606130114.203bb30Review22026-06-13
0.8.12Review22026-06-12
0.8.12-dev.202606122337.5897832Review22026-06-12
0.8.12-dev.202606122239.169d5e4Review52026-06-12
0.8.12-staging.2Review52026-06-12
0.8.11-dev.202606122104.e5b9dd5Review52026-06-12
0.8.11-dev.202606122052.009469eReview52026-06-12
0.8.11-dev.202606122025.f06346fReview22026-06-12
0.8.11-dev.202606121945.5dce801Review52026-06-12
0.8.11-dev.202606121851.26d5122Review22026-06-12
0.8.11-dev.202606121625.5541181Review52026-06-12
0.8.11-dev.202606121512.871577Review22026-06-12
0.8.11-dev.202606121500.871577Review22026-06-12
0.8.12-staging.1Review22026-06-12
0.8.11-dev.202606121323.6ac9407Review22026-06-12
0.8.11-dev.202606121124.ef8e25aReview52026-06-12
0.8.11-dev.202606120935.ef8e25aReview52026-06-12
0.8.11-dev.202606120751.ef8e25aReview52026-06-12
0.8.11-dev.202606120544.842c4c6Review52026-06-12
0.8.11-dev.202606120321.552e02eReview52026-06-12
0.8.11-dev.202606120116.b9ee95bReview52026-06-12
0.8.11-dev.202606120012.5656fc7Review52026-06-12
0.8.11-dev.202606112338.1c15e19Review52026-06-11
0.8.11-dev.202606112241.9ae2fdcReview52026-06-11
0.8.11-dev.202606112147.04177acReview52026-06-11
0.8.11-dev.202606112057.e4bc22eReview52026-06-11
0.8.11Review52026-06-11
0.8.10-dev.202606111910.ead7030Review52026-06-11
0.8.10-dev.202606111724.d4e5462Review52026-06-11
0.8.11-staging.1Review52026-06-11
0.8.10-dev.202606111519.39ad418Review52026-06-11
0.8.10-dev.202606111334.d8a7740Review52026-06-11
0.8.10-dev.202606111255.73ec993Review52026-06-11
0.8.10-dev.202606111245.be4218bReview52026-06-11
0.8.10-dev.202606111140.6a5e88cReview52026-06-11
0.8.10-dev.202606110941.6cb149dReview52026-06-11
0.8.10-dev.202606110755.6cb149dReview52026-06-11
0.8.10-dev.202606110544.2aed335Review52026-06-11
0.8.10-dev.202606110422.8c0e9aaReview52026-06-11
0.8.10-dev.202606110317.792ac3cReview52026-06-11
0.8.10-dev.202606110240.ef9212eReview52026-06-11
0.8.10-dev.202606110112.319a8d3Review52026-06-11
0.8.10-dev.202606110059.319a8d3Review52026-06-11
0.8.10-dev.202606102342.319a8d3Review52026-06-10
0.8.10-dev.202606102253.fbea648Review52026-06-10
0.8.10-dev.202606102242.5285563Review52026-06-10
0.8.10-dev.202606102225.a3947deReview52026-06-10
0.8.10-dev.202606102147.02afd31Review52026-06-10
0.8.10-dev.202606102100.3beeffcReview52026-06-10
0.8.10-dev.202606101903.31e26e6Review52026-06-10
0.8.10-dev.202606101714.d4b22deReview52026-06-10
0.8.10-dev.202606101514.1c52cedReview52026-06-10
0.8.10-dev.202606101436.d73da44Review52026-06-10
0.8.10-dev.202606101324.2fc90b3Review52026-06-10
0.8.10-dev.202606101122.0de2affReview52026-06-10
0.8.10-dev.202606100742.99a7fabReview52026-06-10
0.8.10-dev.202606100925.28c1cfbReview52026-06-10
0.8.10-dev.202606100540.99a7fabReview52026-06-10
0.8.6High risk502026-06-10
0.8.10-dev.202606100317.c8b43c8Review52026-06-10
0.8.10-dev.202606100110.1d2c8c4Review52026-06-10
0.8.10-dev.202606092334.09948c8Review52026-06-09
0.8.10-dev.202606092238.d04fd59Review52026-06-09
0.8.9-dev.202606092139.1f3b646Review52026-06-09
0.8.10Review52026-06-09
0.8.9-dev.202606092047.e63da55Review52026-06-09
0.8.10-staging.1Review52026-06-09
0.8.9-dev.202606091946.122706eReview52026-06-09
0.8.9-dev.202606091926.ebb2d62Review52026-06-09
0.8.9Review52026-06-09
0.8.9-dev.202606091853.fbaa2aeReview52026-06-09
0.8.8-dev.202606091702.2771079Review52026-06-09
0.8.9-staging.5Review52026-06-09
0.8.8-dev.202606091516.3c27bebReview52026-06-09
0.8.8-dev.202606091311.113d87fReview52026-06-09
0.8.9-staging.4Review52026-06-09
0.8.8-dev.202606090339.ad6ec5aReview52026-06-09
0.8.8-dev.202606090318.74794feReview52026-06-09
0.8.8-dev.202606090227.d9f1d29Review52026-06-09
0.8.8-dev.202606090218.6bcb462Review52026-06-09
0.8.8-dev.202606090104.b75d235Review52026-06-09
0.8.8-dev.202606082331.c911d0cReview52026-06-08
0.8.8-dev.202606082236.8dbacc9Review52026-06-08
0.8.9-staging.3Review52026-06-08
0.8.8-dev.202606082140.a5125feReview52026-06-08
0.8.8-dev.202606082058.447e3b6Review52026-06-08
0.8.8-dev.202606081950.5bd40e7Review52026-06-08
0.8.8-dev.202606081859.f7bdc00Review52026-06-08
0.8.8-dev.202606081714.5590368Review52026-06-08
0.8.9-staging.2Review52026-06-08
0.8.8-dev.202606081515.c77a9b6Review52026-06-08
0.8.8-dev.202606081339.938c6ecReview52026-06-08
0.8.9-staging.1Review52026-06-08
0.8.8-dev.202606081143.f600053Review52026-06-08
0.8.8-dev.202606080544.8b7fbffReview52026-06-08
0.8.8-dev.202606080112.5f6d567Review52026-06-08
0.8.8-dev.202606080320.8b7fbffReview52026-06-08
0.8.8-dev.202606080009.0babb76Review52026-06-08
0.8.8-dev.202606072328.6710d73Review52026-06-07
0.8.8-dev.202606072131.4817a81Review52026-06-07
0.8.8-dev.202606072033.0e97ff6Review52026-06-07
0.8.8-dev.202606071935.547b6d2Review52026-06-07
0.8.8-dev.202606071835.08695c1Review52026-06-07
0.8.8-dev.202606071734.db66b83Review52026-06-07
0.8.8-dev.202606071535.f449fc1Review52026-06-07
0.8.8-dev.202606071441.cfe7f13Review52026-06-07
0.8.8-dev.202606071338.2b9914eReview52026-06-07
0.8.8-dev.202606071242.4ca7f3bReview52026-06-07
0.8.8-dev.202606071138.c258385Review52026-06-07
0.8.8-dev.202606071051.c258385Review52026-06-07
0.8.8-dev.202606070049.ca91213Review52026-06-07
0.8.8-dev.202606062128.ca91213Review52026-06-06
0.8.8-dev.202606062031.571ee14Review52026-06-06
0.8.8-dev.202606061935.99a472fReview52026-06-06
0.8.8-dev.202606061835.dc283b1Review52026-06-06
0.8.8-dev.202606061731.f1025b0Review52026-06-06
0.8.8-dev.202606061714.60a1761Review52026-06-06
0.8.8-dev.202606061701.9ee494cReview52026-06-06
0.8.8-dev.202606061631.10cd5feReview52026-06-06
0.8.8-dev.202606061533.1a66375Review52026-06-06
0.8.8-dev.202606061135.a446a08Review52026-06-06
0.8.8-dev.202606061043.373bc8fReview52026-06-06
0.8.8-dev.202606060901.61e1660Review52026-06-06
0.8.8-dev.202606060043.60454adReview52026-06-06
0.8.8-dev.202606052332.17fc8eaReview52026-06-05
0.8.8Review52026-06-05
0.8.7-dev.202606052232.2ddc989Review52026-06-05
0.8.7-dev.202606052220.6efc86dReview52026-06-05
0.8.7-dev.202606052135.3e62c5aReview52026-06-05
0.8.7-dev.202606052118.34cd356Review52026-06-05
0.8.7Review52026-06-03
0.0.1Review52026-05-29

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @vellumai/web (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @vellumai/[email protected]