Package evidence
@newrelic/[email protected]
Remote Dependency Spec: devDependencies.@newrelic/nr-querypack="https://[email protected]/newrelic/nr-querypack"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 259,017Ubiquitous · −70% score
- Versions published
- 478Mature · −50% score
- First published
- May 2022
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@newrelic/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@newrelic/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Dependency Spec: devDependencies.@newrelic/nr-querypack="https://[email protected]/newrelic/nr-querypack"
1 remote tarball(s) were followed statically.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 2 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Dependency Spec | package.json | devDependencies.@newrelic/nr-querypack="https://[email protected]/newrelic/nr-querypack" | 8 |
Remote payloads
Followed remote artifacts
| Source | URL | Risk | Score | Summary |
|---|---|---|---|---|
| devDependencies.@newrelic/nr-querypack | https://[email protected]/newrelic/nr-querypack | error | 0 | invalid gzip header |
Manifest
Package metadata
Scripts31
build:allnpm run cdn:build:local && npm run build:npm && npm run tools:test-buildsbuild:browser-agent-wrappernpm run cdn:build:local && npm run build:npm && npm --prefix tools/test-builds/browser-agent-wrapper run buildbuild:npmnpm run npm:build:esm && npm run npm:build:cjs && npm run npm:build:types && npm run npm:packcdn:buildnpm run cdn:build:prodcdn:build:devnpm run cdn:webpack -- --env mode=devcdn:build:experimentnpm run cdn:webpack -- --env mode=experimentcdn:build:localnpm run cdn:webpackcdn:build:local-externalnpm run cdn:webpack -- --env mode=local-externalcdn:build:prodnpm run cdn:webpack -- --env mode=prodcdn:watchjung -r ./src -F '.*\.test\.js' --run -- npm run cdn:build:localcdn:webpacknpx webpack --progress --config ./tools/webpack/index.mjslinteslint -c .eslintrc.js --ext .js,.cjs,.mjs .lint:fixnpm run lint -- --fixlt:update-browsersnode ./tools/browsers-lists/lt-update-supported.mjslt:upload-webview-assetsnode ./tools/lambda-test/upload-webview-assets.mjsnpm:build:cjsnpx babel --env-name npm-cjs --out-dir dist/cjs --out-file-extension .js ./srcnpm:build:esmnpx babel --env-name npm-esm --out-dir dist/esm --out-file-extension .js ./srcnpm:build:typesnpx tsc -bnpm:packmkdir -p temp && export PKG_NAME=$(npm pack --pack-destination temp) && echo ./temp/$PKG_NAMEpreparehusky installpublish:nrdb:stagenpm --prefix .github/actions install && node .github/actions/nr-upload/index.js --environment=stage --loader-version=$npm_package_version --stage-api-key=$STAGE_API_KEY && node .github/actions/nr-verify/index.js --loader-version=$npm_package_versionstartnpm-run-all --parallel cdn:watch test-servertestNODE_OPTIONS=--max-old-space-size=8192 jesttest-servernode ./tools/wdio/bin/servertest:componentjest --selectProjects componenttest:typesnpm run npm:build:types && tsd -f ./tests/dts/**/*.tstest:unitjest --selectProjects unitthird-party-updatesoss third-party manifest --includeOptDeps && oss third-party notices --includeOptDepstools:test-buildsnpm --prefix ./tools/test-builds run build-allwdionode --max-old-space-size=8192 tools/wdio/bin/cli.js- …and 1 more.
Dependencies3
@newrelic/rrweb^1.1.2fflate0.8.2web-vitals4.2.4