PkgRadar

Package evidence

@rh-support/[email protected]

Remote Dependency Spec: dependencies.hydrajs="git+https://gitlab.cee.redhat.com/redhataccess/hydrajs.git#1.2.9"

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@rh-support/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@rh-support/[email protected]"],"fail_on":"review"}'
Publisherrh-kgarg
Artifact bytes5,212,405
Previous versionnone
Published2019-09-09T13:51:23.256Z
SHA-2566f52df8d1e3f044f1f1b4d244eaccaa439ec8ee83fdb868c50c895731207c488

Why flagged

What the scanner saw

Remote Dependency Spec: dependencies.hydrajs="git+https://gitlab.cee.redhat.com/redhataccess/hydrajs.git#1.2.9"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
28Score
0.0.30Version
Status history (1 event)
  1. newavailable · risk review · score 28 · status changed

Evidence

Static findings

4 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumRemote Dependency Specpackage.jsondependencies.hydrajs="git+https://gitlab.cee.redhat.com/redhataccess/hydrajs.git#1.2.9"12
mediumLarge Javascript Payloadpackage/dist/assets/vendors~index.c0d33d8c.chunk.js7414163 bytes10
Show all 4 findings (low-signal and informational)
SeverityKindPathDetailPoints
mediumRemote Dependency Specpackage.jsondependencies.hydrajs="git+https://gitlab.cee.redhat.com/redhataccess/hydrajs.git#1.2.9"12
mediumLarge Javascript Payloadpackage/dist/assets/vendors~index.c0d33d8c.chunk.js7414163 bytes10
lowObfuscationpackage/dist/assets/vendors~CaseManagement.3838b8b5.chunk.jsmatched "\\u0300"3
lowObfuscationpackage/dist/assets/vendors~polyfill.ae2927ec.chunk.jsmatched "\\x20"3

Manifest

Package metadata

Scripts7
  • buildrm -rf dist && webpack --config ./node_modules/@rh-support/configs/apps/webpack-prod.js --bail --progress --profile && npm run build:server
  • build:devrm -rf dist && webpack --config ./node_modules/@rh-support/configs/apps/webpack-dev.js --bail --progress --profile
  • build:servertsc public/server.ts --allowSyntheticDefaultImports true --esModuleInterop true --skipLibCheck true --outDir dist
  • generate-translationnpm run build && react-gettext-parser --output messages.pot 'dist/assets/*.js'
  • prepublishOnlynpm run build
  • startnode --max-http-header-size=32768 dist/server.js
  • start:devwebpack-dev-server --config ./node_modules/@rh-support/configs/apps/webpack-dev.js --https --cert ./node_modules/@rh-support/configs/apps/server.cert --key ./node_modules/@rh-support/configs/apps/server.key --hot --inline & spandx -c ./node_modules/@rh-support/configs/apps/spandx.config.js
Dependencies33
  • @patternfly/patternfly^2.17.0
  • @patternfly/pfe-accordion^1.0.0-prerelease.10
  • @patternfly/pfelement^1.0.0-prerelease.14
  • @patternfly/react-core^3.38.1
  • @rh-support/api^0.0.30
  • @rh-support/components^0.0.30
  • @rh-support/troubleshoot^0.0.30
  • @rh-support/types^0.0.30
  • @rh-support/utils^0.0.30
  • @webcomponents/webcomponentsjs^2.2.10
  • abortcontroller-polyfill^1.3.0
  • compression^1.7.4
  • connect-history-api-fallback^1.6.0
  • downshift^3.2.7
  • es6-object-assign^1.1.0
  • express^4.17.0
  • hydrajsgit+https://gitlab.cee.redhat.com/redhataccess/hydrajs.git#1.2.9
  • i18next^17.0.1
  • js-markdown-extra^1.2.4
  • jsuri^1.3.1
  • lodash^4.17.15
  • marked^0.7.0
  • morgan^1.9.1
  • promise-polyfill^8.1.0
  • qs^6.7.0
  • react^16.9.0
  • react-bootstrap-typeahead^3.4.3
  • react-dom^16.9.0
  • react-dropzone^10.1.4
  • react-i18next^10.11.0
  • …and 3 more.