PkgRadar

Package evidence

@chromatic-com/[email protected]

Known Indicator Filename: package/embedded/node_modules/fork-ts-checker-webpack-plugin/node_modules/ajv/scripts/bundle.js

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Publisher
GitHub ActionsTrusted automation · −70% score

Effective trust discount applied: 70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@chromatic-com/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@chromatic-com/[email protected]"],"fail_on":"review"}'
Artifact bytes7,024,798
Previous version0.14.2
Published2026-05-22T06:46:13.465Z
SHA-25685892b312258cbf6db2d724dffdbf47a84ead4137722dd1cb73efe93093bf4f8

Why flagged

What the scanner saw

Known Indicator Filename: package/embedded/node_modules/fork-ts-checker-webpack-plugin/node_modules/ajv/scripts/bundle.js

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
71Score
0.14.3-7de78ce-20260522064559Version
Status history (1 event)
  1. newavailable · risk review · score 71 · status changed

Evidence

Static findings

195 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highKnown Indicator Filenamepackage/embedded/node_modules/fork-ts-checker-webpack-plugin/node_modules/ajv/scripts/bundle.jspackage/embedded/node_modules/fork-ts-checker-webpack-plugin/node_modules/ajv/scripts/bundle.js45
mediumRemote Payloadpackage/embedded/node_modules/fork-ts-checker-webpack-plugin/node_modules/ajv/dist/ajv.bundle.jsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/embedded/node_modules/webpack/lib/runtime/GetChunkFilenameRuntimeModule.jsmatched "cUrl "12
mediumObfuscation Densitypackage/embedded/node_modules/html-minifier-terser/src/htmlparser.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/@babel/helper-validator-identifier/lib/identifier.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/json5/dist/index.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/json5/dist/index.min.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/cjs-module-lexer/lexer.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/terser/lib/parse.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/embedded/node_modules/webpack/lib/url/URLParserPlugin.jsmatched "cUrl "12
mediumObfuscation Densitypackage/embedded/node_modules/json5/dist/index.min.mjshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/json5/dist/index.mjshigh encoded/escaped-token density12
Show all 195 findings (low-signal and informational)

Showing 60 of 195 findings.

SeverityKindPathDetailPoints
highKnown Indicator Filenamepackage/embedded/node_modules/fork-ts-checker-webpack-plugin/node_modules/ajv/scripts/bundle.jspackage/embedded/node_modules/fork-ts-checker-webpack-plugin/node_modules/ajv/scripts/bundle.js45
mediumRemote Payloadpackage/embedded/node_modules/fork-ts-checker-webpack-plugin/node_modules/ajv/dist/ajv.bundle.jsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/embedded/node_modules/webpack/lib/runtime/GetChunkFilenameRuntimeModule.jsmatched "cUrl "12
mediumObfuscation Densitypackage/embedded/node_modules/html-minifier-terser/src/htmlparser.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/@babel/helper-validator-identifier/lib/identifier.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/json5/dist/index.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/json5/dist/index.min.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/cjs-module-lexer/lexer.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/terser/lib/parse.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/embedded/node_modules/webpack/lib/url/URLParserPlugin.jsmatched "cUrl "12
mediumObfuscation Densitypackage/embedded/node_modules/json5/dist/index.min.mjshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/embedded/node_modules/json5/dist/index.mjshigh encoded/escaped-token density12
lowObfuscationpackage/embedded/node_modules/eslint-scope/dist/eslint-scope.cjsmatched "eval("3
lowObfuscationpackage/embedded/node_modules/colorette/index.cjsmatched "\\x1b"3
lowObfuscationpackage/embedded/node_modules/@storybook/builder-webpack5/node_modules/es-module-lexer/dist/lexer.cjsmatched "Buffer.from(A,\"base64"3
lowObfuscationpackage/embedded/node_modules/es-module-lexer/dist/lexer.cjsmatched "Buffer.from(A,\"base64"3
lowObfuscationpackage/embedded/node_modules/lodash/_asciiWords.jsmatched "\\x00"3
lowObfuscationpackage/embedded/node_modules/lodash/_createCompounder.jsmatched "\\u2019"3
lowObfuscationpackage/embedded/node_modules/lodash/_deburrLetter.jsmatched "\\xc0"3
lowObfuscationpackage/embedded/node_modules/lodash/_escapeStringChar.jsmatched "\\u2028"3
lowObfuscationpackage/embedded/node_modules/lodash/_hasUnicode.jsmatched "\\ud800"3
lowObfuscationpackage/embedded/node_modules/lodash/_unicodeSize.jsmatched "\\ud800"3
lowObfuscationpackage/embedded/node_modules/lodash/_unicodeToArray.jsmatched "\\ud800"3
lowObfuscationpackage/embedded/node_modules/lodash/_unicodeWords.jsmatched "\\ud800"3
lowObfuscationpackage/embedded/node_modules/acorn/dist/acorn.jsmatched "\\u200c"3
lowObfuscationpackage/embedded/node_modules/fork-ts-checker-webpack-plugin/node_modules/ajv/dist/ajv.bundle.jsmatched "\\x00"3
lowObfuscationpackage/embedded/node_modules/fork-ts-checker-webpack-plugin/node_modules/ajv/dist/ajv.min.jsmatched "\\x00"3
lowObfuscationpackage/embedded/node_modules/renderkid/lib/AnsiPainter.jsmatched "\\x1b"3
lowObfuscationpackage/embedded/node_modules/webpack/lib/asset/AssetGenerator.jsmatched "Buffer.from(content, \"base64"3
lowObfuscationpackage/embedded/node_modules/yaml/browser/dist/schema/yaml-1.1/binary.jsmatched "atob("3
lowObfuscationpackage/embedded/node_modules/yaml/dist/schema/yaml-1.1/binary.jsmatched "Buffer.from(src, 'base64"3
lowObfuscationpackage/embedded/node_modules/source-map-support/browser-source-map-support.jsmatched "fromCharCode"3
lowObfuscationpackage/embedded/node_modules/terser/dist/bundle.min.jsmatched "\\u2028"3
lowObfuscationpackage/embedded/node_modules/webpack/lib/cli.jsmatched "\\u001B"3
lowObfuscationpackage/embedded/node_modules/webpack-hot-middleware/client.jsmatched "\\uD83D"3
lowObfuscationpackage/embedded/node_modules/ajv/dist/compile/codegen/code.jsmatched "\\u2028"3
lowObfuscationpackage/embedded/node_modules/anymatch/node_modules/picomatch/lib/constants.jsmatched "\\x00"3
lowObfuscationpackage/embedded/node_modules/braces/lib/constants.jsmatched "\\u00A0"3
lowObfuscationpackage/embedded/node_modules/picomatch/lib/constants.jsmatched "\\x00"3
lowObfuscationpackage/embedded/node_modules/readdirp/node_modules/picomatch/lib/constants.jsmatched "\\x00"3
lowObfuscationpackage/embedded/node_modules/cssesc/cssesc.jsmatched "\\x20"3
lowObfuscationpackage/embedded/node_modules/webpack/lib/css/CssParser.jsmatched "fromCharCode"3
lowObfuscationpackage/embedded/node_modules/yaml/browser/dist/parse/cst.jsmatched "\\x02"3
lowObfuscationpackage/embedded/node_modules/yaml/dist/parse/cst.jsmatched "\\x02"3
lowObfuscationpackage/embedded/node_modules/webpack/lib/util/dataURL.jsmatched "Buffer.from(body, \"base64"3
lowObfuscationpackage/embedded/node_modules/lodash/deburr.jsmatched "\\xc0"3
lowObfuscationpackage/embedded/node_modules/entities/lib/decode_codepoint.jsmatched "fromCharCode"3
lowObfuscationpackage/embedded/node_modules/@webassemblyjs/utf8/esm/decoder.jsmatched "fromCharCode"3
lowObfuscationpackage/embedded/node_modules/@webassemblyjs/utf8/lib/decoder.jsmatched "fromCharCode"3
lowObfuscationpackage/embedded/node_modules/@webassemblyjs/utf8/src/decoder.jsmatched "fromCharCode"3
lowObfuscationpackage/embedded/node_modules/webpack/lib/stats/DefaultStatsPrinterPlugin.jsmatched "\\u001B"3
lowObfuscationpackage/embedded/node_modules/cosmiconfig/node_modules/yaml/dist/Document-9b4560a1.jsmatched "\\x00"3
lowObfuscationpackage/embedded/node_modules/terser/tools/domprops.jsmatched "fromCharCode"3
lowObfuscationpackage/embedded/node_modules/entities/lib/encode.jsmatched "\\x7F"3
lowObfuscationpackage/embedded/node_modules/webpack/lib/EvalDevToolModulePlugin.jsmatched "eval("3
lowObfuscationpackage/embedded/node_modules/webpack/lib/EvalSourceMapDevToolPlugin.jsmatched "eval("3
lowObfuscationpackage/embedded/node_modules/terser/lib/compress/evaluate.jsmatched "eval("3
lowObfuscationpackage/embedded/node_modules/ajv-formats/dist/formats.jsmatched "\\x00"3
lowObfuscationpackage/embedded/node_modules/fork-ts-checker-webpack-plugin/node_modules/ajv/lib/compile/formats.jsmatched "\\x00"3
lowObfuscationpackage/embedded/node_modules/javascript-stringify/dist/function.jsmatched "\\xA0"3

Manifest

Package metadata

Scripts5
  • buildyarn prebuild && tsup
  • cleanrimraf ./dist ./embedded
  • prebuildyarn clean
  • test:playwrightplaywright test
  • test:unityarn workspace @chromaui/chromatic-e2e test:unit --project Playwright
Dependencies3
  • @chromaui/rrweb-snapshot2.0.0-alpha.19-noAbsolute
  • @segment/analytics-node2.1.3
  • storybook10.2.13