PkgRadar

Package evidence

@genesislcap/[email protected]

Credential File Packaged: package/.env

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
547Mature · −50% score
First published
May 2024
Publisher
genesisnpm

Effective trust discount applied: 50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@genesislcap/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@genesislcap/[email protected]"],"fail_on":"high"}'
Publishergenesisnpm
Artifact bytes121,127
Previous version14.458.1-GENC-0.2
Published2026-06-13T15:45:06.837Z
SHA-256f1e507d692b7adde5754f5742365a400485ca6cddeb6160d1f11a6f888a5a258

Why flagged

What the scanner saw

Credential File Packaged: package/.env

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
17Score
14.458.1-GENC-0.3Version
Status history (1 event)
  1. newavailable · risk high · score 17 · status changed

Evidence

Static findings

1 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highCredential File Packagedpackage/.envpackage/.env35

Manifest

Package metadata

Scripts27
  • baselinenpm run clean && npm run bootstrap
  • bootstrapnpm install --no-fund --no-audit
  • bootstrap:cinpm ci --no-fund --no-audit
  • buildgenx build -b ts
  • build:statsgenx analyze
  • build:webpackgenx build
  • build:webpack:statsgenx analyze
  • cleanrimraf dist node_modules
  • devgenx dev
  • dev:dockernpm run dev -- --host 0.0.0.0
  • dev:httpsnpm run dev -- --https
  • dev:intellijgenx dev -e ENABLE_SSO
  • dev:no-opennpm run dev -- --no-open
  • dev:webpacknpm run dev -- -b webpack
  • dsconfigdsconfig --path src/styles/design-tokens.json
  • git:setupcd .. && npx --yes husky install
  • lintgenx lint -l ox
  • lint:eslintgenx lint -l eslint --profile
  • lint:fixgenx lint -l ox --fix
  • lint:stylelintgenx lint -l stylelint
  • servegenx serve
  • testgenx test
  • test:coveragegenx test --coverage
  • test:e2egenx test --e2e
  • test:e2e:debuggenx test --e2e --debug
  • test:e2e:uigenx test --e2e --interactive
  • test:unit:watchgenx test --watch
Dependencies15
  • @genesislcap/foundation-comms14.458.1-GENC-0.3
  • @genesislcap/foundation-events14.458.1-GENC-0.3
  • @genesislcap/foundation-layout14.458.1-GENC-0.3
  • @genesislcap/foundation-logger14.458.1-GENC-0.3
  • @genesislcap/foundation-notifications14.458.1-GENC-0.3
  • @genesislcap/foundation-shell14.458.1-GENC-0.3
  • @genesislcap/foundation-store14.458.1-GENC-0.3
  • @genesislcap/foundation-ui14.458.1-GENC-0.3
  • @genesislcap/foundation-utils14.458.1-GENC-0.3
  • @genesislcap/foundation-zero14.458.1-GENC-0.3
  • @genesislcap/foundation-zero-grid-pro14.458.1-GENC-0.3
  • @genesislcap/g2plot-chart14.458.1-GENC-0.3
  • @genesislcap/rapid-design-system14.458.1-GENC-0.3
  • @genesislcap/rapid-grid-pro14.458.1-GENC-0.3
  • @genesislcap/web-core14.458.1-GENC-0.3