Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 1
- First published
- Jun 2026
- Publisher
- zaisuf
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@codilore/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@codilore/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts6
dbbun drizzle-kitfix-node-ptybun run script/fix-node-pty.tsmigrationbun run script/migration.tstestbun testtest:cimkdir -p .artifacts/unit && bun test --timeout 30000 --reporter=junit --reporter-outfile=.artifacts/unit/junit.xmltypechecktsgo --noEmit
Dependencies59
@ai-sdk/alibaba1.0.17@ai-sdk/amazon-bedrock4.0.107@ai-sdk/anthropic3.0.71@ai-sdk/azure3.0.49@ai-sdk/cerebras2.0.41@ai-sdk/cohere3.0.27@ai-sdk/deepinfra2.0.41@ai-sdk/gateway3.0.104@ai-sdk/google3.0.73@ai-sdk/google-vertex4.0.128@ai-sdk/groq3.0.31@ai-sdk/mistral3.0.27@ai-sdk/openai3.0.53@ai-sdk/openai-compatible2.0.41@ai-sdk/perplexity3.0.26@ai-sdk/provider3.0.8@ai-sdk/provider-utils4.0.23@ai-sdk/togetherai2.0.41@ai-sdk/vercel2.0.39@ai-sdk/xai3.0.82@aws-sdk/credential-providers3.993.0@codilore/effect-drizzle-sqlite1.15.13@codilore/effect-sqlite-node1.15.13@codilore/llm1.15.13@effect/opentelemetry^1.15.13@effect/platform-node^1.15.13@effect/sql-sqlite-bun^1.15.13@lydell/node-pty^1.15.13@npmcli/arborist9.4.0@npmcli/config10.8.1- …and 29 more.