PkgRadar

Package evidence

@heartlandone/vega-sandbox-pr-2962-56ee0a8b6fbe49d22d429742fea93686343a2270@2.85.0

Credential file access: matched ".azure"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
1
First published
May 2026
Publisher
aprilzhu

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@heartlandone/vega-sandbox-pr-2962-56ee0a8b6fbe49d22d429742fea93686343a2270@2.85.0"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@heartlandone/vega-sandbox-pr-2962-56ee0a8b6fbe49d22d429742fea93686343a2270@2.85.0"],"fail_on":"review"}'
Publisheraprilzhu
Artifact bytes7,171,249
Previous versionnone
Published2026-05-25T09:26:26.766Z
SHA-25677c63493879331d367a2a8e7459ec6b406ab824bcca0d76290d871c9799c2351

Why flagged

What the scanner saw

Credential file access: matched ".azure"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
115Score
2.85.0Version
Status history (1 event)
  1. newavailable · risk review · score 115 · status changed

Evidence

Static findings

56 static · 0 from release diff · showing high-signal first.

No high-signal findings — see all findings below.

Show all 56 findings (low-signal and informational)
SeverityKindPathDetailPoints
lowCredential file accesspackage/dist/esm/index-bfc6dfa2.jsmatched ".azure"5
lowCredential file accesspackage/dist/cjs/index-f054eb5d.jsmatched ".azure"5
lowCredential file accesspackage/dist/vega/p-5a25014f.jsmatched ".azure"5
lowObfuscationpackage/dist/esm/code-block-10be3916.jsmatched "\\u200b"3
lowObfuscationpackage/dist/cjs/code-block-c6c70464.jsmatched "\\u200b"3
lowObfuscationpackage/dist/collection/components/vega-rich-text-editor/constants/constant.jsmatched "\\u200b"3
lowObfuscationpackage/dist/esm/polyfills/core-js.jsmatched "\\uD800"3
lowObfuscationpackage/dist/collection/polyfill/prism/languages/css.jsmatched "\\u00B7"3
lowObfuscationpackage/dist/collection/polyfill/d3/d3-scale-polyfill.jsmatched "\\u2212"3
lowObfuscationpackage/dist/esm/index-bfc6dfa2.jsmatched "fromCharCode"3
lowObfuscationpackage/dist/cjs/index-f054eb5d.jsmatched "fromCharCode"3
lowObfuscationpackage/dist/collection/polyfill/prism/languages/javascript.jsmatched "\\xA0"3
lowObfuscationpackage/dist/vega/p-13e7f906.entry.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-1ec763ab.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-2ae5acfc.entry.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-3d0ba2c6.entry.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-423762ae.entry.jsmatched "\\x01"3
lowObfuscationpackage/dist/vega/p-5a25014f.jsmatched "fromCharCode"3
lowObfuscationpackage/dist/vega/p-613ddaab.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-6817b9bd.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-818da356.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-aacf6920.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-aaf44879.entry.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-af00e6e2.entry.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-c51ebb14.entry.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-c78fe943.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-d402eb7b.entry.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-e47b2c4c.entry.jsmatched "\\x3c"3
lowObfuscationpackage/dist/vega/p-e95cb28f.entry.jsmatched "\\xA0"3
lowObfuscationpackage/dist/vega/p-ed26f4c8.entry.jsmatched "\\x3c"3
lowObfuscationpackage/dist/collection/polyfill/prism/tokenizer.jsmatched "\\x00"3
lowObfuscationpackage/dist/collection/polyfill/prism/languages/typescript.jsmatched "\\xA0"3
lowObfuscationpackage/dist/collection/constants/validator.jsmatched "\\x01"3
lowObfuscationpackage/dist/collection/components/vega-app-footer/vega-app-footer.jsmatched "\\u00A9"3
lowObfuscationpackage/dist/collection/components/vega-calendar/vega-calendar.jsmatched "\\u00B1"3
lowObfuscationpackage/dist/cjs/vega-code-block.cjs.entry.jsmatched "\\x00"3
lowObfuscationpackage/dist/esm/vega-code-block.entry.jsmatched "\\x00"3
lowObfuscationpackage/dist/collection/components/vega-date-picker/vega-date-picker-calendar/vega-date-picker-calendar.jsmatched "\\u00B1"3
lowObfuscationpackage/dist/collection/components/vega-date-picker/vega-date-picker.jsmatched "\\u00B1"3
lowObfuscationpackage/dist/collection/components/vega-input-numeric/vega-input-numeric.jsmatched "\\u2014"3
lowObfuscationpackage/dist/collection/components/vega-input-passcode/vega-input-passcode.jsmatched "\\u2014"3
lowObfuscationpackage/dist/collection/components/vega-input-phone-number/vega-input-phone-number.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cjs/vega-input.cjs.entry.jsmatched "\\x01"3
lowObfuscationpackage/dist/esm/vega-input.entry.jsmatched "\\x01"3
lowObfuscationpackage/dist/collection/components/vega-input/vega-input.jsmatched "\\u2014"3
lowObfuscationpackage/dist/collection/components/vega-nav/vega-left-nav-link/vega-left-nav-link.jsmatched "\\u2019"3
lowObfuscationpackage/dist/collection/components/vega-popover/vega-popover.jsmatched "\\u2018"3
lowObfuscationpackage/dist/cjs/vega-signature-capture.cjs.entry.jsmatched "atob("3
lowObfuscationpackage/dist/esm/vega-signature-capture.entry.jsmatched "atob("3
lowObfuscationpackage/dist/collection/components/vega-textarea/vega-textarea.jsmatched "\\u2014"3
lowObfuscationpackage/dist/collection/components/vega-time-picker/vega-time-picker.jsmatched "\\u2715"3
lowObfuscationpackage/dist/collection/components/vega-tooltip/vega-tooltip-content-box/vega-tooltip-content-box.jsmatched "\\u00A0"3
lowObfuscationpackage/dist/collection/components/vega-tooltip/vega-tooltip.jsmatched "\\u00A0"3
lowObfuscationpackage/dist/collection/components/vega-signature-capture/slimmers/written-mode/controllers/written-mode-svg-controller.jsmatched "atob("3
lowObfuscationpackage/dist/cjs/y-axis-input-processor-54a26515.jsmatched "\\u2212"3
lowObfuscationpackage/dist/esm/y-axis-input-processor-c7e05353.jsmatched "\\u2212"3

Manifest

Package metadata

Scripts57
  • buildnpm run build:base -- --docs && node scripts/update-toobigrc-for-new-files-only.js
  • build-components-definitionnpm run setup:base && npx stencil build -- --docs-json docs/components-definition.json
  • build-components-type-definitionnpx typedoc src/types/public-api.ts --json docs/components-type-definition.json
  • build-feature-flagsnode ./scripts/build-feature-flags.js
  • build-migrationnode ./scripts/build-migration.js
  • build-storybookbuild-storybook --quiet
  • build:basenpx patch-package && npm run setup && npx stencil build
  • check-feature-flagsnode ./scripts/check-feature-flags.js
  • clean:test:visualnode scripts/visual-test-screenshot-handle.js
  • clean:test:visual:pipelineNODE_ENV=pipeline npm run clean:test:visual
  • consume-design-tokennode ./scripts/consume_vega_design_output.js
  • debugnpm run prepare:postcss -- -w | npm run build:base -- --dev --watch --serve --debug --no-cache
  • generatestencil generate
  • generate-export-components-typesnode ./scripts/generate-export-components-types.js && npx prettier -w ./src/types/components.type.d.ts
  • generate-export-typenode ./scripts/generate-export-types-checking.js && npx prettier -w ./src/types/test/exported-type.ts
  • lintnpm run setup && npm run lint:build-bundles && npm run lint:ts:export-type && npm run lint:ts:strict && npm run lint:ts:base && npm run lint:prettier && npm run lint:eslint && npm run lint:e2e-module && npm run lint:test-case
  • lint:build-bundlesnode scripts/build-bundles-config.js
  • lint:e2e-modulenode scripts/e2e-test-module-validation.js
  • lint:eslintnpx eslint --max-warnings=0 src
  • lint:prettiernpx prettier -c .
  • lint:test-casenode scripts/test-case-vaildation.js
  • lint:ts:basetsc -p ./tsconfig.json --noEmit
  • lint:ts:export-typeyarn generate-export-type && tsc -p ./tsconfig.type-check.json --noEmit
  • lint:ts:stricttsc -p ./tsconfig.strict.json --noEmit
  • postbuildcp dist/vega/*.css style/ && npm run postbuild:SRI && npm run postbuild:ensure-dist-dts && npm run postbuild:angular && npm run postbuild:vue && npm run postbuild:react && npm run postbuild:dist-check && npm run postbuild:verify-no-test-in-dist
  • postbuild-storybookmkdir -p storybook-static/vega && cp dist/vega/vega.css storybook-static/vega/vega.css
  • postbuild:SRInode ./scripts/subresource-integrity/sri-setup.js
  • postbuild:angularnpm run stencil-postbuild --prefix ../vega-angular-workspace/projects/vega-angular
  • postbuild:dist-checknode ./scripts/components-dynamic-import-path-validation.js
  • postbuild:ensure-dist-dtsnode ./scripts/ensure-dist-dts.js
  • …and 27 more.
Dependencies2
  • @heartlandone/vega-telemetry-install-ledgers^1.1.0
  • @heartlandone/vega-telemetry-runtime-metrics^1.0.10