Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 2,580Niche · −30% score
- Versions published
- 117
- First published
- Apr 2026
- Publisher
- mwashburn160
Effective trust discount applied: −30% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@pipeline-builder/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@pipeline-builder/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts11
buildpnpm dlx projen buildcompilepnpm dlx projen compiledefaultpnpm dlx projen defaulteslintpnpm dlx projen eslintpackagepnpm dlx projen packagepost-compilepnpm dlx projen post-compilepre-compilepnpm dlx projen pre-compileprojenpnpm dlx projentestpnpm dlx projen testtest:watchpnpm dlx projen test:watchwatchpnpm dlx projen watch
Dependencies19
@opentelemetry/api1.9.1@opentelemetry/auto-instrumentations-node0.76.0@opentelemetry/exporter-trace-otlp-http0.218.0@opentelemetry/instrumentation0.218.0@opentelemetry/resources2.7.1@opentelemetry/sdk-node0.218.0@pipeline-builder/api-core3.4.71@pipeline-builder/pipeline-core3.4.79compression1.8.1cors2.8.6express5.2.1express-rate-limit8.5.2helmet8.2.0ioredis5.11.1jsonwebtoken9.0.3prom-client15.1.3rate-limit-redis5.0.0swagger-ui-express5.0.1uuid14.0.0