Package evidence
@sentry/[email protected]
Suspicious Publish Context: {"package_age_days":0,"publisher":"sentry-bot","burst_same_day":1,"burst_week":4,"lure":{"kind":"token_affix","target":"canvas"},"version_anomaly":true,"new_account":false}
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 1
- First published
- Jun 2026
- Publisher
- sentry-bot
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@sentry/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@sentry/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Suspicious Publish Context: {"package_age_days":0,"publisher":"sentry-bot","burst_same_day":1,"burst_week":4,"lure":{"kind":"token_affix","target":"canvas"},"version_anomaly":true,"new_account":false}
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 10 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Suspicious Publish Context | manifest | {"package_age_days":0,"publisher":"sentry-bot","burst_same_day":1,"burst_week":4,"lure":{"kind":"token_affix","target":"canvas"},"version_anomaly":true,"new_account":false} | 10 |
Manifest
Package metadata
Scripts20
buildrun-p build:transpile build:types build:bundlebuild:bundlerollup -c rollup.bundle.config.mjsbuild:bundle:watchyarn build:bundle --watchbuild:devrun-p build:transpile build:typesbuild:dev:watchrun-p build:transpile:watchbuild:tarballnpm packbuild:transpilerollup -c rollup.npm.config.mjsbuild:transpile:watchyarn build:transpile --watchbuild:typesrun-s build:types:core build:types:downlevelbuild:types:coretsc -p tsconfig.types.jsonbuild:types:downlevelyarn downlevel-dts build/npm/types build/npm/types-ts3.8 --to ts3.8build:watchrun-p build:transpile:watch build:bundle:watchcircularDepCheckmadge --circular src/index.tscleanrimraf build sentry-replay-*.tgzlintOXLINT_TSGOLINT_DANGEROUSLY_SUPPRESS_PROGRAM_DIAGNOSTICS=true oxlint . --type-awarelint:es-compatibilityes-check es2020 ./build/{bundles,npm/cjs}/*.js && es-check es2020 ./build/npm/esm/*.js --modulelint:fixOXLINT_TSGOLINT_DANGEROUSLY_SUPPRESS_PROGRAM_DIAGNOSTICS=true oxlint . --fix --type-awaretestvitest runtest:watchvitest --watchyalc:publishyalc publish --push --sig
Dependencies2
@sentry/core10.58.0@sentry/replay10.58.0