Package evidence
@lukso/[email protected]
Remote Dependency Spec: devDependencies.forge-std="github:foundry-rs/forge-std#v1.9.7"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 2
- First published
- Aug 2025
- Publisher
- lukso-network
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@lukso/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@lukso/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Dependency Spec: devDependencies.forge-std="github:foundry-rs/forge-std#v1.9.7"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 8 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Dependency Spec | package.json | devDependencies.forge-std="github:foundry-rs/forge-std#v1.9.7" | 8 |
Manifest
Package metadata
Scripts15
buildforge buildbuild:artifactsbash script/packageArtifacts.shbuild:jstsupbuild:packagebash script/buildPackage.shbuild:typechaintypechain --target=ethers-v5 --out-dir typechain ./artifacts/*.jsonbuild:wagmiwagmi generatecleanrm -rf cache out artifacts typechain dist abi.ts build.loglintbun run lint:sol && bun run prettier:checklint:solforge fmt --check && bun solhint {script,src,test}/**/*.solprettier:checkprettier --check "**/*.{json,md,yml}" --ignore-path ".prettierignore"prettier:writeprettier --write "**/*.{json,md,yml}" --ignore-path ".prettierignore"testforge testtest:coverageforge coveragetest:coverage:reportforge coverage --report lcov && genhtml lcov.info --branch-coverage --output-dir coveragetest:gasforge test --gas-report
Dependencies4
@erc725/smart-contracts-v8npm:@erc725/[email protected]@hyperlane-xyz/core^8.1.1@lukso/lsp7-contracts^0.16.8@lukso/lsp8-contracts^0.16.7