PkgRadar

npm · registry.npmjs.org

drizzle-kit

Large Javascript Payload: 8220840 bytes

Why PkgRadar flagged 1.0.0-rc.3-abc2ef6

SeveritySignalEvidence
mediumLarge Javascript Payload8220840 bytes · package/api-mysql.js
mediumLarge Javascript Payload8554684 bytes · package/api-postgres.js
mediumLarge Javascript Payload9284528 bytes · package/bin.cjs
mediumLarge Javascript Payload9233138 bytes · package/index.mjs
mediumLarge Javascript Payload8220807 bytes · package/api-sqlite.js
mediumLarge Javascript Payload8218548 bytes · package/api-sqlite.mjs
mediumLarge Javascript Payload8218577 bytes · package/api-mysql.mjs
mediumLarge Javascript Payload9241996 bytes · package/index.js
mediumLarge Javascript Payload8550225 bytes · package/api-postgres.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.31.10Low risk02026-06-15
1.0.0-rc.3-abc2ef6Review272026-05-27
1.0.0-rc.4-ca0f029Review282026-05-27

Block this in CI

PkgRadar gates drizzle-kit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]