PkgRadar

npm · registry.npmjs.org

@veupathdb/clinepi-site

Large Javascript Payload: 3592121 bytes

Why PkgRadar flagged 1.4.0

SeveritySignalEvidence
mediumLarge Javascript Payload3592121 bytes · package/dist/bundles/legacy/555.bundle-9b08831200c69436199d.js
mediumLarge Javascript Payload3592147 bytes · package/dist/bundles/modern/555.bundle-9b08831200c69436199d.js
mediumLarge Javascript Payload3804560 bytes · package/dist/bundles/legacy/605.bundle-02a3eaa4fb4de23c8c00.js
mediumLarge Javascript Payload3817297 bytes · package/dist/bundles/modern/605.bundle-02a3eaa4fb4de23c8c00.js
mediumLarge Javascript Payload6307452 bytes · package/dist/bundles/legacy/site-client.bundle.js
mediumLarge Javascript Payload6368169 bytes · package/dist/bundles/modern/site-client.bundle.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.9Low risk02026-06-11
1.4.8Low risk02026-06-10
1.4.6Low risk02026-06-09
1.4.7Low risk02026-06-09
1.3.6-patch-26Low risk02026-06-08
1.4.5Low risk02026-06-08
1.4.4Low risk02026-06-03
1.4.2Low risk02026-05-29
1.4.3Low risk02026-05-29
1.4.0Review182026-05-25
1.4.1Review182026-05-25

Block this in CI

PkgRadar gates @veupathdb/clinepi-site (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @veupathdb/[email protected]