Package evidence
@db-ux/[email protected]
Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 1 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 147Mature · −50% score
- First published
- Feb 2025
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@db-ux/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@db-ux/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 1 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 4 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Manifest Codeless Dependency Stub | package.json | package ships no JS/TS source but declares 1 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape | 15 |
Manifest
Package metadata
Scripts33
buildrun-s build-components build-assets && pnpm run build-style:01_sass && pnpm run build-style:02_postcssbuild-assetscpr src build --overwrite --filter "(.ts|.tsx|.md|.html)$"build-componentspnpm run build:mitosis && pnpm run build-components:post && pnpm run build-components:docsbuild-components:docspnpm --filter @db-ux/wc-core-components run build:cembuild-components:posttsx scripts/post-build/index.tsbuild-style:01_sasssass src:build --no-source-map --load-path=node_modulesbuild-style:02_postcsspostcss build/**/*.css --replacebuild:mitosismitosis build --config configs/mitosis.config.cjscompile:angularmitosis build --config configs/angular/mitosis.config.cjs && tsx scripts/exec/angular.ts && cpr ../../output/tmp/angular/src ../../output/angular/src --overwritecompile:reactmitosis build --config configs/react/mitosis.config.cjs && tsx scripts/exec/react.ts && cpr ../../output/tmp/react/src ../../output/react/src --overwritecompile:stencilmitosis build --config configs/stencil/mitosis.config.cjs && tsx scripts/exec/stencil.ts && cpr ../../output/tmp/stencil/src ../../output/stencil/src --overwritecompile:vuemitosis build --config configs/vue/mitosis.config.cjs && tsx scripts/exec/vue.ts && cpr ../../output/tmp/vue/src ../../output/vue/src --overwritecopy-assetscpr ../foundations/assets build/assets -ocopy-outputrun-p copy:*copy:agentcpr agent ../../build-outputs/components/agent --overwritecopy:changelogcpr CHANGELOG.md ../../build-outputs/components/CHANGELOG.md --overwritecopy:outputscpr build ../../build-outputs/components/build --overwritecopy:package.jsoncpr package.json ../../build-outputs/components/package.json --overwritecopy:readmecpr README.md ../../build-outputs/components/README.md --overwritedev:angularnodemon --watch src --watch scripts --watch configs --ext tsx,ts,cjs --exec "npm run compile:angular"dev:htmlpnpm run copy-assets && pnpm run build-assets && pnpm run build-style:01_sass && vite --opendev:reactnodemon --watch src --watch scripts --watch configs --ext tsx,ts,cjs --exec "pnpm run compile:react"dev:scsssass src:build --load-path=node_modules --watch --source-mapdev:stencilnodemon --watch src --watch scripts --watch configs --ext tsx,ts,cjs --exec "pnpm run compile:stencil"dev:vuenodemon --watch src --watch scripts --watch configs --ext tsx,ts,cjs --exec "pnpm run compile:vue"generate:agentmitosis build --config=configs/mitosis.agent.config.cjsgenerate:componenthygen mitosis newgenerate:docshygen update-docs newgenerate:figmamitosis build --config=configs/mitosis.figma.config.cjsgenerate:showcasemitosis build --config=configs/mitosis.showcase.config.cjs- …and 3 more.
Dependencies1
@db-ux/core-foundations4.10.2