PkgRadar

Package evidence

@mlightcad/[email protected]

Remote Payload: matched "raw.githubusercontent.com"

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@mlightcad/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@mlightcad/[email protected]"],"fail_on":"review"}'
Publishermlight.li
Artifact bytes817,711
Previous version1.7.39
Published2026-05-25T05:17:00.342Z
SHA-2561d73b7bc148f8b8fd3de23c9d4289b562914afa88f4bbb5309727d5e304b730c

Why flagged

What the scanner saw

Remote Payload: matched "raw.githubusercontent.com"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
21Score
1.7.40Version
Status history (1 event)
  1. newavailable · risk review · score 21 · status changed

Evidence

Static findings

4 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumRemote Payloadpackage/lib/misc/AcDbMLeaderStyleColorCodec.jsmatched "raw.githubusercontent.com"12
Show all 4 findings (low-signal and informational)
SeverityKindPathDetailPoints
mediumRemote Payloadpackage/lib/misc/AcDbMLeaderStyleColorCodec.jsmatched "raw.githubusercontent.com"12
lowObfuscationpackage/dist/data-model.cjsmatched "\\x00"3
lowObfuscationpackage/lib/base/AcDbDxfFiler.jsmatched "\\x00"3
lowObfuscationpackage/dist/dxf-parser-worker.jsmatched "fromCharCode"3

Manifest

Package metadata

Scripts9
  • analyzepnpm run analyze:lib && pnpm run analyze:worker
  • analyze:libvite build --mode analyze --config vite.config.main.ts
  • analyze:workervite build --mode analyze --config vite.config.worker.ts
  • buildtsc && pnpm run build:lib && pnpm run build:worker
  • build:libvite build --config vite.config.main.ts
  • build:workervite build --config vite.config.worker.ts
  • cleanrimraf dist lib tsconfig.tsbuildinfo
  • linteslint src/
  • lint:fixeslint --fix --quiet src/
Dependencies6
  • @mlightcad/common1.4.40
  • @mlightcad/dxf-json^1.2.0
  • @mlightcad/geometry-engine3.2.40
  • @mlightcad/graphic-interface3.3.40
  • iconv-lite^0.7.0
  • uid^2.0.2