Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 2
- First published
- May 2026
- Publisher
- zhen.hz
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@cainiaofe/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@cainiaofe/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 2319544 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 100 · status changed
Evidence
Static findings
18 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/dist/cn-ai-table-plugin-lite-onecode-m.js | 2319544 bytes | 10 |
| medium | Large Javascript Payload | package/dist/cn-ai-table-plugin-lite-onecode-pc.js | 2319546 bytes | 10 |
| medium | Large Javascript Payload | package/dist/cn-ai-table-plugin-onecode-m.js | 2417556 bytes | 10 |
| medium | Large Javascript Payload | package/dist/cn-ai-table-plugin-onecode-pc.js | 2417558 bytes | 10 |
| medium | Large Javascript Payload | package/dist/cn-domain-ai-table-lite-onecode-m.js | 2396123 bytes | 10 |
| medium | Large Javascript Payload | package/dist/cn-domain-ai-table-lite-onecode-pc.js | 2396125 bytes | 10 |
| medium | Large Javascript Payload | package/dist/cn-domain-ai-table-onecode-m.js | 2494152 bytes | 10 |
| medium | Large Javascript Payload | package/dist/cn-domain-ai-table-onecode-pc.js | 2494154 bytes | 10 |
| medium | Large Javascript Payload | package/dist/prototypeView-lite-onecode-m.js | 2392948 bytes | 10 |
| medium | Large Javascript Payload | package/dist/prototypeView-lite-onecode-pc.js | 2392950 bytes | 10 |
| medium | Large Javascript Payload | package/dist/prototypeView-onecode-m.js | 2490965 bytes | 10 |
| medium | Large Javascript Payload | package/dist/prototypeView-onecode-pc.js | 2490967 bytes | 10 |
| medium | Large Javascript Payload | package/dist/prototypeView.js | 2490967 bytes | 10 |
| medium | Large Javascript Payload | package/dist/view-lite-onecode-m.js | 2392896 bytes | 10 |
| medium | Large Javascript Payload | package/dist/view-lite-onecode-pc.js | 2392898 bytes | 10 |
| medium | Large Javascript Payload | package/dist/view-onecode-m.js | 2490882 bytes | 10 |
| medium | Large Javascript Payload | package/dist/view-onecode-pc.js | 2490884 bytes | 10 |
| medium | Large Javascript Payload | package/dist/view.js | 2490884 bytes | 10 |
Manifest
Package metadata
Scripts11
buildcone build && npm run build:npmbuild:librarynode build/library-es-lib-build.jsbuild:npmnpm run build:libraryeslinteslint --ext .js,.jsx,.ts,.tsx src --fixpre-commitlint-stagedpreparehuskystartcone startstart:mconcurrently -n onecode-m,storybook "node ./build/onecode-m-start.js" "DEV=1 UA_MODE=mobile ./node_modules/.bin/storybook dev -p 9921"start:pcconcurrently -n onecode-pc,storybook "node ./build/onecode-pc-start.js" "DEV=1 UA_MODE=pc ./node_modules/.bin/storybook dev -p 9920"stylelintstylelint "src/**/*.scss" --fixtestjest
Dependencies28
@cainiaofe/cn-domain-popup^1.0.1@cainiaofe/cn-i18n0.3.21@cainiaofe/cn-request^2.0.0@cainiaofe/cn-ui^0.x@cainiaofe/cn-ui-theme-light^2.x@codemirror/autocomplete^6.18.6@codemirror/commands^6.8.1@codemirror/lang-javascript^6.2.3@codemirror/language^6.10.8@codemirror/state^6.5.2@codemirror/view^6.36.5@dnd-kit/core^6.3.1@dnd-kit/modifiers^9.0.0@dnd-kit/sortable^10.0.0@dnd-kit/utilities^3.2.2@floating-ui/react-dom^2.1.8@formulajs/formulajs^4.4.9@ice/stark-data^0.1.3@lezer/highlight^1.2.1copy-to-clipboard^3.3.3dayjs^1.11.10expr-eval^2.0.2mobx^6.15.0mobx-react-lite^4.1.1react-markdown^8.0.7react-syntax-highlighter^15.5.0recorder-core^1.3.25011100remark-gfm^3.0.1