PkgRadar

npm · registry.npmjs.org

lalph

Large Javascript Payload: 7757998 bytes

Why PkgRadar flagged 0.3.134

SeveritySignalEvidence
mediumLarge Javascript Payload7757998 bytes · package/dist/cli.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.137Low risk02026-06-11
0.3.136Low risk02026-06-11
0.3.135Low risk02026-06-03
0.3.134Review32026-05-28
0.3.132Review32026-05-27
0.3.133Review32026-05-27

Block this in CI

PkgRadar gates lalph (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]