Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 163
- Versions published
- 10Established · −30% score
- First published
- Sep 2023
- Publisher
- ajmeese7
Effective trust discount applied: −30% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Block this updateStatic evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@meese-os/[email protected]"],"fail_on":"high"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@meese-os/[email protected]"],"fail_on":"high"}'Why flagged
What the scanner saw
Credential File Packaged: package/src/client/.env
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk high · score 24 · status changed
Evidence
Static findings
11 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Credential File Packaged | package/src/client/.env | package/src/client/.env | 35 |
Show all 11 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Credential File Packaged | package/src/client/.env | package/src/client/.env | 35 |
| low | Large Javascript Payload | package/dist/meeseOS.02d3e68088be262063ac.bundle.js | 2476881 bytes | 0 |
| low | Large Javascript Payload | package/dist/meeseOS.2844b52b918e41067122.bundle.js | 2476953 bytes | 0 |
| low | Large Javascript Payload | package/dist/meeseOS.36f341886057c812e7d9.bundle.js | 2477050 bytes | 0 |
| low | Large Javascript Payload | package/dist/meeseOS.52965dcab209a9c7de35.bundle.js | 2477111 bytes | 0 |
| low | Large Javascript Payload | package/dist/meeseOS.61f76d1ae6d303469cc9.bundle.js | 2476899 bytes | 0 |
| low | Large Javascript Payload | package/dist/meeseOS.9c41a43759c686959cdb.bundle.js | 2476877 bytes | 0 |
| low | Large Javascript Payload | package/dist/scripts/meeseOS.aae8dc10eef0db3d0f33.bundle.js | 2476928 bytes | 0 |
| low | Large Javascript Payload | package/dist/meeseOS.c5687fc8d35a460ee1f1.bundle.js | 2477031 bytes | 0 |
| low | Large Javascript Payload | package/dist/scripts/meeseOS.c7672b0e0373c36258a1.bundle.js | 2476889 bytes | 0 |
| low | Obfuscation Density | package/.rush/temp/shrinkwrap-deps.json | high encoded/escaped-token density | 0 |
Manifest
Package metadata
Scripts18
buildwebpack && npm run build:manifestbuild:manifestmeese-cli package:discoverbuild:productionNODE_ENV=production rush builddeployNODE_ENV=production npm run serveeslinteslint src/client/**/*.js src/server/**/*.jsmake:applicationmeese-cli make:applicationmake:authmeese-cli make:authmake:iframe-applicationmeese-cli make:iframe-applicationmake:providermeese-cli make:providermake:settingsmeese-cli make:settingsmake:vfsmeese-cli make:vfspackage:createmeese-cli package:createpackage:discovermeese-cli package:discoverpublish:dryrush publish --include-allservenode src/server/index.jsstylelintstylelint src/client/*.scss --fix --quiet-deprecation-warningstestnpm run eslint && npm run stylelintwatchwebpack --watch
Dependencies32
@meese-os/cli1.0.1@meese-os/client1.0.0@meese-os/cyberchef1.0.0@meese-os/dialogs1.0.0@meese-os/dynamic-wallpapers1.0.0@meese-os/filemanager1.0.0@meese-os/games1.0.0@meese-os/gnome-icons1.0.0@meese-os/google-api-provider1.0.0@meese-os/gui1.0.0@meese-os/image-to-8bit1.0.0@meese-os/old-site1.0.0@meese-os/panels1.0.0@meese-os/preview1.0.0@meese-os/server1.0.0@meese-os/settings1.0.0@meese-os/sounds1.0.0@meese-os/standard-dark-theme1.0.0@meese-os/standard-theme1.0.0@meese-os/static-wallpapers1.0.0@meese-os/terminal1.0.0@meese-os/textpad1.0.0@meese-os/uptime-monitor1.0.0@meese-os/we10x-icons1.0.0@meese-os/widgets1.0.0@meese-os/windows8-theme1.0.0@meese-os/wireless-tools-provider1.0.0complex-dotenv-json^1.1.0dotenv^16.3.1hyperapp^1.2.10- …and 2 more.