Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 3,648Niche · −30% score
- Versions published
- 1,050Mature · −50% score
- First published
- May 2025
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@aurodesignsystem-dev/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@aurodesignsystem-dev/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 4640015 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 12 · status changed
Evidence
Static findings
5 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/components/form/demo/customize.min.js | 4640015 bytes | 10 |
| medium | Large Javascript Payload | package/components/form/demo/getting-started.min.js | 4640015 bytes | 10 |
| medium | Large Javascript Payload | package/components/form/demo/index.min.js | 4639953 bytes | 10 |
| medium | Large Javascript Payload | package/components/form/demo/registerDemoDeps.min.js | 4618739 bytes | 10 |
Show all 5 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/components/form/demo/customize.min.js | 4640015 bytes | 10 |
| medium | Large Javascript Payload | package/components/form/demo/getting-started.min.js | 4640015 bytes | 10 |
| medium | Large Javascript Payload | package/components/form/demo/index.min.js | 4639953 bytes | 10 |
| medium | Large Javascript Payload | package/components/form/demo/registerDemoDeps.min.js | 4618739 bytes | 10 |
| low | Credential file access | package/custom-elements.json | matched ".azure" | 3 |
Manifest
Package metadata
Scripts39
analyzecustom-elements-manifest analyze --config ./packages/config/src/custom-elements-manifest.config.mjsbuildnpm run analyze && npm run build:docs:kit && turbo run buildbuild-storybooknpm run build && npm run analyze && storybook buildbuild:docsturbo run build:docsbuild:docs:kitnode ./packages/build-tools/src/kitDocProcessor.mjsbuild:forcenpm run analyze && turbo run build --forcebuild:formkit-versionturbo run build:formkit-versionbuild:versionturbo run build:versioncleanturbo run clean && rm -rf node_modulesdeploy-demonpm run build && sh ./deploy-components.shdevturbo run dev --paralleldev:closedturbo run dev:closed --paralleldev:reactconcurrently "npx turbo run build:watch --concurrency=20" "npm run dev:app:open --workspace=apps/react-framework"dev:svelteconcurrently "npx turbo run build:watch --concurrency=20" "npm run dev:app:open --workspace=apps/svelte-framework"formatprettier --write "**/*.{ts,tsx,md}"lintturbo run lintlocal-demosh ./local-demo.shlocal-demo:buildnpm run build && npm run local-demolocal-demo:zipnpm run local-demo:build -- --zippreCommitnode ./node_modules/@aurodesignsystem/auro-library/scripts/build/pre-commit.mjspreparehuskysassturbo run sassstorybooknpm run analyze && storybook dev -p 6006sweepfind ./components ./packages -type d -name 'dist' -exec rm -rf {} + && find ./ -type d -name '.turbo' -exec rm -rf {} + && find ./components ./packages -not -path '*/node_modules/*' -type f -name '*-css.js' -delete && find ./components -path '*/demo/*.md' -delete && find ./components -path '*/demo/*.min.js' -delete && find ./components -path '*/demo/*.min.css' -deletetestnpm run test:wtr && npm run test:frameworkstest:dashboardnode test/coverage/generate-dashboard.mjstest:forceturbo run test --force --continuetest:framework:reactturbo run test:framework --filter=@aurodesignsystem/react-frameworktest:framework:report:reactnpm run test:framework:report -w apps/react-frameworktest:framework:report:sveltenpm run test:framework:report -w apps/svelte-framework- …and 9 more.
Dependencies5
@lit/context^1.1.6@lit/reactive-element^2.1.2lit^3.3.2lit-element^4.1.1lit-html^3.2.1
Optional dependencies2
@rolldown/binding-linux-x64-gnu*@rollup/rollup-linux-x64-gnu*