Package evidence
@1024pix/[email protected]
Install-time lifecycle script: preinstall="npx check-engine"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 2,307Niche · −30% score
- Versions published
- 527Mature · −50% score
- First published
- Dec 2021
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@1024pix/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@1024pix/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Install-time lifecycle script: preinstall="npx check-engine"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 1 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 1 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Install-time lifecycle script | package.json | preinstall="npx check-engine" | 5 |
Manifest
Package metadata
Scripts27
build./scripts/build.shbuild-emberember build --environment=productionbuild-storybookember build && cp -v CNAME dist && storybook buildcleanrm -rf dist node_modulesdeploy-storybookstorybook-to-ghpagesdevnpm-run-all --parallel serve-ember serve-storybooklintnpm-run-all --aggregate-output --parallel --continue-on-error 'lint:!(fix)'lint:fixnpm-run-all --aggregate-output --parallel --continue-on-error lint:*:fixlint:hbsember-template-lint .lint:hbs:fixnpm run lint:hbs -- --fixlint:jseslint .lint:js:fixnpm run lint:js -- --fixlint:scssstylelint app/styles/*.scss addon/styles/*.scss 'addon/styles/**/*.scss'lint:scss:fixnpm run lint:scss -- --fixpreinstallnpx check-engineprestorybookember buildserve-emberember serveserve-storybookstorybook dev --port 9001 --no-openstartember servestorybooknpm run devsvg:compilesvg-sprite -C 'svgs/svg-sprite.config.json' 'svgs/icons/*.svg'svg:generate-spritenpm run svg:compile && npm run svg:optimize && npm run svg:rename-idsvg:optimizesvgo --config='svgs/svgo.config.js' -i 'public/svg/' -o 'public/svg/'svg:rename-idbash ./svgs/rename-icon-id-in-sprite.shtestember testtest:emberember testtest:ember-compatibilityember try:each
Dependencies14
@babel/core^7.25.2@formatjs/intl^4.0.0check-engine^1.14.0ember-auto-import^2.7.4ember-cli-babel^8.2.0ember-cli-htmlbars^6.3.0ember-cli-sass^11.0.1ember-click-outside^6.1.1ember-lifeline^7.0.0ember-modifier^4.2.0ember-popperjs^3.0.0ember-template-imports^4.3.0ember-truth-helpers^5.0.0tracked-toolbox^2.2.0