Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 52
- Versions published
- 3
- First published
- May 2016
- Publisher
- economist-org-bot
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@economist/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@economist/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts35
accessnpm-run-all --parallel access:*access:publicnpm access public $npm_package_name || trueaccess:sudonpm access grant read-write economist:read-write-all $npm_package_name || truebuildnpm-run-all --parallel build:*build:csscp $npm_package_directories_src/*.css $npm_package_directories_libbuild:jsbabel $npm_package_directories_src -d $npm_package_directories_lib --source-maps inlinedocnpm-run-all --parallel doc:*doc:assetsnpm-assets $npm_package_directories_sitedoc:csspostcss $npm_package_config_doc_css_options -o $npm_package_directories_site/bundle.css $npm_package_directories_src/example.cssdoc:htmlhbs -D package.json -H @economist/doc-pack -o $npm_package_directories_site $npm_package_config_doc_html_filesdoc:jsbrowserify $npm_package_config_doc_js_options $npm_package_directories_test/*.js -o $npm_package_directories_site/bundle.jslintnpm-run-all --parallel lint:*lint:cssstylelint $npm_package_directories_src/*.csslint:jseslint --ignore-path .gitignore .pagesgit-directory-deploy --directory $npm_package_directories_site --branch gh-pagespostpublishnpm run accessposttestlcov-result-merger 'coverage/**/lcov.info' | coveralls; trueprebuild:cssmkdir -p $npm_package_directories_libpredocmkdir -p $npm_package_directories_siteprepagesnpm run docprepublishnpm run buildpretestnpm run lint && npm run docprewatch:docnpm run predocprewatch:servewhile [ ! -f site/index.html ]; do sleep 1; doneprovisionprovision-react-componentsemantic-releasesemantic-release pre || exit 0; npm publish && semantic-release poststartnpm run watchtestkarma startwatchnpm-run-all --parallel watch:*watch:docnpm-run-all --parallel watch:doc:*- …and 5 more.
Dependencies2
lodash.uniqueid^4.0.0react^0.14.8