Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@conboai/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@conboai/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 6419206 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 24 · status changed
Evidence
Static findings
3 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/dist/index-e042726d.js | 6419206 bytes | 10 |
| medium | Large Javascript Payload | package/dist/mapbox-gl-iS0lrrWp-537973f8.js | 2214665 bytes | 10 |
Show all 3 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/dist/index-e042726d.js | 6419206 bytes | 10 |
| medium | Large Javascript Payload | package/dist/mapbox-gl-iS0lrrWp-537973f8.js | 2214665 bytes | 10 |
| low | Install-time lifecycle script | package.json | prepare="husky" | 4 |
Manifest
Package metadata
Scripts24
buildyarn build:check && vite buildbuild-storybookstorybook buildbuild:checktscdevviteformatprettier --write "src/**/*.{ts,tsx,json}" --colorformat-checkprettier "src/**/*.{ts,tsx,json}" --checkgenerate-classifiersopenapi --input https://api.dev.conbo.app/classification/docs-yaml --output ./src/api/classifiersgenerate-deploymentsopenapi --input https://api.admin.conbo.app/deployment/docs-yaml --output ./src/api/deploymentsgenerate-eventsopenapi --input https://api.dev.conbo.app/events/docs-yaml --output ./src/api/eventsgenerate-floor-planopenapi --input https://api.dev.conbo.app/floorplan/docs-yaml --output ./src/api/floorPlangenerate-imagesopenapi --input https://api.dev.conbo.app/images/docs-yaml --output ./src/api/imagesgenerate-optimusopenapi --input https://api.dev.conbo.app/optimus/docs-yaml --output ./src/api/optimusgenerate-path-analysisopenapi --input https://api.dev.conbo.app/ldm/docs-yaml --output ./src/api/path-analysisgenerate-positionopenapi --input https://api.dev.conbo.app/position/docs-yaml --output ./src/api/positiongenerate-query-infoopenapi --input https://api.dev.conbo.app/info/docs-yaml --output ./src/api/queryInfogenerate-query-topopenapi --input https://api.dev.conbo.app/query-top/docs-yaml --output ./src/api/queryTopgenerate-searchopenapi --input https://api.dev.conbo.app/search/docs-yaml --output ./src/api/searchgenerate-snapshotsopenapi --input https://api.dev.conbo.app/snapshots/docs-yaml --output ./src/api/snapshotgenerate-top-oneopenapi --input https://api.dev.conbo.app/top1/docs-yaml --output ./src/api/topOnelinteslint . --ext ts,tsx --report-unused-disable-directiveslint-fixeslint . --ext ts,tsx --fixpreparehuskypreviewvite previewstorybookstorybook dev -p 6006
Dependencies22
@conboai/storybook.components0.6.71@emotion/react^11.11.4@emotion/styled^11.11.5@hookform/resolvers^3.9.1@mui/icons-material^6.1.7@mui/material^6.1.7@mui/system^6.1.7@mui/x-data-grid^7.22.2@mui/x-data-grid-pro^7.22.2@mui/x-date-pickers^7.22.2@react-google-maps/api^2.19.3ajv^8.20.0await-to-js^3.0.0dayjs^1.11.13lodash^4.17.21lodash.debounce^4.0.8react^18.2.0react-dom^18.2.0react-hook-form^7.53.2uuid^9.0.1zod^3.23.8zustand^4.5.2