Package evidence
@brizy/[email protected]
Remote Dependency Spec: dependencies.antd="https://github.com/bagrinsergiu/ant-design/archive/refs/heads/4.7.0-fix-rc-select-v6.tar.gz"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 108
- Versions published
- 190Mature · −50% score
- First published
- Mar 2020
- Publisher
- lift46252
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@brizy/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@brizy/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Dependency Spec: dependencies.antd="https://github.com/bagrinsergiu/ant-design/archive/refs/heads/4.7.0-fix-rc-select-v6.tar.gz"
1 remote tarball(s) were followed statically.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 7 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Remote Dependency Spec | package.json | dependencies.antd="https://github.com/bagrinsergiu/ant-design/archive/refs/heads/4.7.0-fix-rc-select-v6.tar.gz" | 12 |
| medium | Remote Dependency Spec | package.json | dependencies.react-custom-scrollbars="github:bagrinsergiu/react-custom-scrollbars#4.2.1.3-rc" | 12 |
Remote payloads
Followed remote artifacts
| Source | URL | Risk | Score | Summary |
|---|---|---|---|---|
| dependencies.antd | https://github.com/bagrinsergiu/ant-design/archive/refs/heads/4.7.0-fix-rc-select-v6.tar.gz | error | 0 | unexpected end of file |
Manifest
Package metadata
Scripts14
buildnpm run clean && npm run build:es && npm run build:lib && npm run build:distbuild:distNODE_ENV=production gulp buildbuild:esNODE_ENV=production tscbuild:libNODE_ENV=production npm run build:es -- --module commonjs --outDir libcleanrimraf es/ lib/ dist/i18ni18next && ../../.github/workflows/ci_cd/localization.shlinteslint .prepacknpm i && npm run buildprettier:checkprettier --config ../../.prettierrc --ignore-path ../../.prettierignore --check "**/*.{js,jsx,ts,tsx,mdx,md}"prettier:writeprettier --config ../../.prettierrc --ignore-path ../../.prettierignore --write "**/*.{js,jsx,ts,tsx,mdx,md}"startconcurrently --kill-others "tsc --watch" "tsc --watch --module commonjs --outDir lib" "gulp build ---watch"stylelintstylelint --config stylelint.config.js "./src/**/*.less"testNODE_ENV=test TZ=UTC jesttsctsc --noEmit
Dependencies32
@ant-design/cssinjs^1.23.0@ant-design/icons^6.0.0@brizy/ui-icons^0.0.50@loadable/component^5.16.4@popperjs/core^2.11.8antdhttps://github.com/bagrinsergiu/ant-design/archive/refs/heads/4.7.0-fix-rc-select-v6.tar.gzantd-v5npm:antd@^5.22.3cheerio1.0.0-rc.12classnames^2.5.1codemirror^5.65.18downshift^3.4.8fuzzy-search^3.2.1i18next^23.16.5lottie-react^2.4.0lottie-web^5.12.2moment^2.30.1ramda0.27.1react-codemirror2^8.0.0react-color^2.19.3react-custom-scrollbarsgithub:bagrinsergiu/react-custom-scrollbars#4.2.1.3-rcreact-draggable^4.4.6react-facebook^9.0.12react-i18next^11.17.2react-player^2.16.0react-popper^2.3.0react-quill^2.0.0react-transition-group^4.4.5react-virtualized-auto-sizer^1.0.24react-virtuoso^3.1.5tailwindcss^3.4.15- …and 2 more.