PkgRadar

npm · registry.npmjs.org

icve-urc

Large Javascript Payload: 7170678 bytes

Why PkgRadar flagged 2.8.158

SeveritySignalEvidence
mediumLarge Javascript Payload7170678 bytes · package/dist/icve-urc.common.js
mediumLarge Javascript Payload7171158 bytes · package/dist/icve-urc.umd.js
mediumLarge Javascript Payload2726717 bytes · package/dist/icve-urc.umd.min.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.8.165Low risk02026-06-13
2.8.164Low risk02026-06-13
2.8.163Low risk02026-06-12
2.8.162Low risk02026-06-12
2.8.161Low risk02026-06-11
2.8.159Low risk02026-06-10
2.8.158Review302026-05-25
2.8.155Review302026-05-25
2.8.157Review302026-05-25

Block this in CI

PkgRadar gates icve-urc (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]