Package evidence
@afwenming123/[email protected]
Install-time lifecycle script: postinstall="node scripts/postinstall || echo \"ignore\""
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 128
- Versions published
- 8
- First published
- May 2026
- Publisher
- zhangzhenyu_125306
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@afwenming123/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@afwenming123/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Install-time lifecycle script: postinstall="node scripts/postinstall || echo \"ignore\""
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 5 · status changed
Evidence
Static findings
3 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 3 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Install-time lifecycle script | package.json | postinstall="node scripts/postinstall || echo \"ignore\"" | 5 |
| low | Large Javascript Payload | package/dist/antd-with-locales.js | 4686615 bytes | 0 |
| low | Large Javascript Payload | package/dist/antd.js | 4377413 bytes | 0 |
Manifest
Package metadata
Scripts17
codecovcodecovcompilenode antd-tools/cli/run.js compiledevwebpack-dev-serverdistnode antd-tools/cli/run.js distlinteslint -c ./.eslintrc --fix --ext .jsx,.js,.vue ./componentslint:docseslint -c ./.eslintrc --fix --ext .jsx,.js,.vue,.md ./antdv-demo/docs/**/demo/**lint:siteeslint -c ./.eslintrc --fix --ext .jsx,.js,.vue ./antdv-demolint:stylestylelint "{site,components}/**/*.less" --syntax lesspostinstallnode scripts/postinstall || echo "ignore"pre-publishnode ./scripts/prepubprepublishnode antd-tools/cli/run.js guardprettierprettier -c --write '**/*'pretty-quickpretty-quickpubnode antd-tools/cli/run.js pubpub-with-cinode antd-tools/cli/run.js pub-with-cistartcross-env NODE_ENV=development webpack-dev-server --config webpack.config.jstestcross-env NODE_ENV=test jest --config .jest.js
Dependencies30
@ant-design/icons^2.1.1@ant-design/icons-vue^2.0.0@simonwep/pickr~1.7.0add-dom-event-listener^1.0.2array-tree-filter^2.1.0async-validator^3.0.3babel-helper-vue-jsx-merge-props^2.0.3babel-runtime6.xclassnames^2.2.5component-classes^1.2.6dom-align^1.10.4dom-closest^0.2.0dom-scroll-into-view^2.0.0enquire.js^2.1.6intersperse^1.0.0is-mobile^2.2.1is-negative-zero^2.0.0ismobilejs^1.0.0json2mq^0.2.0lodash^4.17.5moment^2.21.0mutationobserver-shim^0.3.2node-emoji^1.10.0omit.js^1.0.0raf^3.4.0resize-observer-polyfill^1.5.1shallow-equal^1.0.0shallowequal^1.0.2vue-ref^2.0.0warning^4.0.0