Package evidence
@massalabs/[email protected]
Remote Dependency Spec: devDependencies.as-bignum="github:massalabs/as-bignum#0105eb596b2fa707c00712e811a2efdfcb8a9848"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 65
- Versions published
- 16
- First published
- Apr 2026
- Publisher
- damip
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@massalabs/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@massalabs/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Dependency Spec: devDependencies.as-bignum="github:massalabs/as-bignum#0105eb596b2fa707c00712e811a2efdfcb8a9848"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 8 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Dependency Spec | package.json | devDependencies.as-bignum="github:massalabs/as-bignum#0105eb596b2fa707c00712e811a2efdfcb8a9848" | 8 |
Manifest
Package metadata
Scripts38
add:currency-to-registrytsx src/add-currency-to-registry.tsapprove:p-layer-proposaltsx src/approve-p-layer-proposal.tsapprove:proposaltsx src/approve-proposal.tsbuildnpx massa-as-compileburn:fundstsx src/burn-funds.tsdeploytsx src/deploy.tsexecute:proposaltsx src/execute-proposal.tsfmtnpm run prettier:fix && npm run lint:fixfmt:checknpm run prettier && npm run lintgenerate:decc-notsx src/generate-decc-no.tsgenerate:wallettsx src/generate-wallet.tsget:available-currency-infotsx src/get-available-currency-info.tsget:currency-multisig-infotsx src/get-currency-multisig-info.tsget:decc-balancetsx src/get-decc-balance.tsget:multisig-parameterstsx src/get-multisig-parameters.tslinteslint .lint:fixeslint . --fixlist:p-layer-proposalstsx src/list-p-layer-proposals.tslist:proposalstsx src/list-proposals.tsopen:decctsx src/open-decc.tsprepublishOnlynpm run buildprettierprettier assembly//**/*.ts --checkprettier:fixprettier assembly//**/*.ts --writepropose:add-membertsx src/propose-add-member.tspropose:currency-pausetsx src/propose-currency-pause.tspropose:execution-delaytsx src/propose-execution-delay.tspropose:freeze_accounttsx src/propose-freeze-account.tspropose:minttsx src/propose-mint.tspropose:replace-membertsx src/propose-replace-member.tspropose:revoke-membertsx src/propose-revoke-member.ts- …and 8 more.