Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 9,322Niche · −30% score
- Versions published
- 3,317Mature · −50% score
- First published
- Sep 2020
- Publisher
- corva-devops-automation
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@corva/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@corva/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 2688769 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 1 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Large Javascript Payload | package/mcp-server/server.mjs | 2688769 bytes | 0 |
Manifest
Package metadata
Scripts36
buildyarn generate-css-themes && cross-env SHELL=sh ./scripts/build.sh productionbuild-devyarn generate-css-themes && cross-env SHELL=sh ./scripts/build.sh developmentbuild-storybookyarn generate-css-themes && IS_STORYBOOK_BUILD=true storybook build -c storybook --docsbuild-watchyarn generate-css-themes && cross-env SHELL=sh ./scripts/build.sh development --watchcheck-duplicationsecho "👀 Checking code duplications" && jscpd src --silentchoreyarn release -- --prereleasefigma:dry-runfigma connect publish --dry-runfigma:dry-run-filefigma connect publish --dry-run --filefigma:publishfigma connect publishfigma:publish-filefigma connect publish --filefigma:unpublishfigma connect unpublishfigma:unpublish-filefigma connect unpublish --filefigma:unpublish-node-forcenode scripts/figma-unpublish-node-force.mjsgenerate-css-themesnode ./scripts/generateCssThemesVariables.mjsget-changelogconventional-changelog -r 2 -p angularhelper-clinpx @corva/fe-dev-helper-cli@latestlinteslint --cache ./src/lint-stagedlint-stagedmcp:buildyarn mcp:generate-data && yarn mcp:generate-prompts && yarn mcp:bundlemcp:bundlerollup -c rollup.mcp.config.js && chmod 755 dist/mcp-server/server.mjs dist/mcp-server/setup.mjsmcp:devyarn --silent mcp:generate-data && yarn --silent mcp:generate-prompts && tsx mcp-server/bin/mcp-server.tsmcp:generate-datatsx mcp-server/src/data-generator/index.tsmcp:generate-promptstsx mcp-server/src/prompts-generator/index.tsmcp:inspectyarn --silent mcp:generate-data && yarn --silent mcp:generate-prompts && npx @modelcontextprotocol/inspector tsx mcp-server/bin/mcp-server.tsmcp:report-missed-lookupstsx mcp-server/uptrace/missed-lookups/report-missed-lookups.tsmcp:testyarn --silent mcp:generate-prompts && jest --config mcp-server/jest.config.jsmcp:test:watchyarn --silent mcp:generate-prompts && jest --config mcp-server/jest.config.js --watchreleasegit fetch --tags && git add -A && standard-version -astartyarn generate-css-themes && cross-env NODE_ENV=local rollup -c -wstorybookyarn generate-css-themes && IS_STORYBOOK_BUILD=true storybook dev -p 6006 -c storybook --docs- …and 6 more.
Dependencies99
@apidevtools/swagger-parser^12.1.0@badgateway/oauth2-client2.2.4@date-io/moment1.3.13@icon-park/react^1.4.2@mapbox/mapbox-gl-draw^1.5.1@mapbox/tilebelt^2.0.3@material-ui/core4.11.2@material-ui/icons4.9.1@material-ui/lab4.0.0-alpha.57@material-ui/pickers3.2.10@modelcontextprotocol/sdk^1.29.0@opentelemetry/api~1.9.0@opentelemetry/exporter-metrics-otlp-http~0.57.0@opentelemetry/exporter-trace-otlp-http~0.57.0@opentelemetry/resources~1.30.0@opentelemetry/sdk-metrics~1.30.0@opentelemetry/sdk-trace-node~1.30.0@opentelemetry/semantic-conventions~1.30.0@rollbar/react^0.11.1@tanstack/react-query4.35.3@turf/bbox^7.3.0@turf/circle^7.3.0@vis.gl/react-mapbox^8.1.0auth0-js^9.14.0chalk4.1.1chroma-js1.4.1classnames2.2.6corva-convert-units1.32.0dompurify3.2.4dotenv^10.0.0- …and 69 more.