Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 202
- Versions published
- 19
- First published
- May 2026
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@cngxjs/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@cngxjs/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 3535647 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 6 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/dist/index-cli-DFOfVqDM.js | 3535647 bytes | 10 |
| medium | Large Javascript Payload | package/dist/index-cli-cBvysffE.mjs | 3493416 bytes | 10 |
Manifest
Package metadata
Scripts35
*********BUILD************************************QUALITY************************************TEST E2E************************************TEST************************************UTILS***************************buildtsdown && node scripts/postbuild-shebang.mjs && npm run build-schematics && npm run build:client && npm run build:css && npm run build:themesbuild-schematicstsc --project schematics/tsconfig.json && cp schematics/collection.json dist && cp schematics/ng-add/schema.json dist/schematics/ng-add/schema.jsonbuild:clienttsdown --config tsdown.client.config.tsbuild:csstailwindcss -i src/styles/compodocx.css -o src/resources/styles/compodocx.css --minifybuild:themesnode -e "const fs=require('fs'),p=require('path');fs.readdirSync('src/themes').filter(f=>f.endsWith('.css')&&f!=='theme-template.css').forEach(f=>fs.copyFileSync(p.join('src/themes',f),p.join('src/resources/styles',f)))"changelogauto-changelog -o CH.md --template tools/changelog-template.hbs -udevnode scripts/dev-watch.mjsdev:modulenode scripts/dev-watch.mjs --fixture=kitchen-sink-module --port=8080dev:standalonenode scripts/dev-watch.mjs --fixture=kitchen-sink-standalone --port=8081download-api-listnode tools/download-api-list.jsformat:checkbiome formatformat:writebiome format --writelintbiome checklint:fixbiome check --fixmadge./node_modules/.bin/madge --warning -i dist/madge.png src/index-cli.tsprebuildrimraf distpretestnpm run buildstartnpm run test:watchtestnpm run test:unit && npm run test:clitest-e2e-playwrightnpx playwright testtest:allvitest runtest:clivitest run test/src/clitest:migratevitest run test/src/migratetest:multi-version-docnode ./scripts/build-multi-version-fixture.mjstest:simple-docnode ./bin/index-cli.js --no-multiVersion -p ./test/fixtures/sample-files/tsconfig.simple.json -d doc -s --port 4000 --toggleMenuItems modules,components,directives,classes,injectables,interceptors,guards,pipes,interfaces,miscellaneous,additionalPages- …and 5 more.
Dependencies29
@compodoc/ngd-transformer^2.1.3@kitajs/html^4.2.13@polka/send-type^0.5.2@stackblitz/sdk^1.11.0body-parser^2.2.2cheerio^1.2.0chokidar^5.0.0commander^14.0.2cosmiconfig^9.0.0d3^7.9.0decache^4.6.2fast-glob^3.3.3fs-extra^11.3.3glob^13.0.0handlebars^4.7.8html-entities^2.6.0i18next25.7.4json5^2.2.3marked7.0.3minimist^1.2.8neotraverse^0.6.18os-name4.0.1picocolors^1.1.1polka^0.5.2semver^7.7.3shiki^4.0.2sirv^3.0.2ts-morph^27.0.2uuid11.1.0