Package evidence
@pareto-engineering/[email protected]
Install-time lifecycle script: postinstall="node ./scripts/postinstall.js"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 43
- Versions published
- 99Mature · −50% score
- First published
- Jul 2021
- Publisher
- johnpareto
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@pareto-engineering/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@pareto-engineering/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Install-time lifecycle script: postinstall="node ./scripts/postinstall.js"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 2 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 1 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Install-time lifecycle script | package.json | postinstall="node ./scripts/postinstall.js" | 5 |
Manifest
Package metadata
Scripts34
build-storybookbuild-storybook -s ./src/assets/images,./node_modules/@pareto-engineering/assets/images,./node_modules/@pareto-engineering/assets/fontsbuild:cjsnpm run compile:cjs && npm run copy-css:cjsbuild:esnpm run compile:es && npm run copy-css:eschromaticchromatic --project-token=ab9c4393a209compilenpm run build:es && npm run build:cjscompile:cjsCOMPILE_ENV=cjs babel src/ui --extensions '.js,.jsx' --out-dir dist/cjscompile:esCOMPILE_ENV=es babel src/ui --extensions '.js,.jsx' --out-dir dist/escopy-css:cjscopyfiles -u 2 src/ui/**/*.scss dist/cjscopy-css:escopyfiles -u 2 src/ui/**/*.scss dist/esfetch-schemanpm run fetch-schema:prodfetch-schema:devnode scripts/fetchSchema.jsfetch-schema:prodnode scripts/fetchSchema.js -- --ref productionfix:eslintnpm run test:eslint -- --fixfix:stylelintnpm run test:stylelint -- --fixinstall:hooksgit config --local core.hooksPath .githooks/link:allnpm run link:bem && npm run link:styles && npm run link:assets && npm run link:dslink:assetsnpm link @pareto-engineering/assetslink:bemnpm link @pareto-engineering/bemlink:dsnpm link @pareto-engineering/design-systemlink:stylesnpm link @pareto-engineering/stylespostinstallnode ./scripts/postinstall.jspreparenpm run compileprepare:watchnodemon --watch src --ignore 'src/stories' --exec 'npm run build:es' && echo donerelayrelay-compilerstorybookstart-storybook --no-manager-cache -p 6007 -s ./src/assets/images,./node_modules/@pareto-engineering/assets/images,./node_modules/@pareto-engineering/assets/fontstestnpm run test:stylelint && npm run test:eslint && npm run test:jesttest:eslinteslint --ext .jsx,.js src/test:jestjesttest:jest:updatejest --updateSnapshottest:stylelintstylelint src/**/*.scss --rd --rdd --risd --color --formatter verbose- …and 4 more.
Dependencies27
@pareto-engineering/assets^2.0.0-alpha.24@pareto-engineering/bem^0.1.5@pareto-engineering/design-system^2.0.0-alpha.70@pareto-engineering/styles^2.0.0-alpha.8date-fns^2.23.0downshift^6.1.7formik^2.2.9fuse.js^6.5.3hamburgers^1.1.3name0.0.2prop-types^15.7.2query-string^7.0.0react^17.0.2react-countup^4.4.0react-dom^17.0.2react-helmet^6.1.0react-quill^1.3.5react-redux^7.2.6react-relay^11.0.2react-router-dom^5.3.1react-table^7.7.0react-visibility-sensor^5.1.1redux^4.1.2relay-runtime^11.0.2relay-test-utils^11.0.2swiper^6.7.5typed.js^2.0.12