PkgRadar

Package evidence

@signageos/[email protected]

no findings

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
906
Versions published
135Mature · −50% score
First published
May 2018
Publisher
signageos.io

Effective trust discount applied: 50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Looks clean — keep monitoring

No high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@signageos/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@signageos/[email protected]"],"fail_on":"review"}'
Publishersignageos.io
Artifact bytes1,630,505
Previous version8.6.0
Published2026-04-24T13:03:27.907Z
SHA-2567bae5eccffe8f7bf3ca7789374dce72d36b71e35c439d284285812b060c7b968

Why flagged

What the scanner saw

No high-signal static finding in the saved report.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

low
Last checked
lowRisk
0Score
8.7.0Version
Status history (1 event)
  1. newavailable · risk low · score 0 · status changed

Evidence

Static findings

No findings stored for this release.

Manifest

Package metadata

Scripts19
  • buildNODE_OPTIONS=--openssl-legacy-provider webpack --config=webpack.config.js && npm run escheck
  • checknpm run depcheck && npx --userconfig ./.npmrc @signageos/lib check-deps
  • check-typestsc --noEmit
  • cleanrm -rf dist/* es6/*
  • clean-buildnpm run clean && npm run build && npm run generate-declarations && npm run generate-docs
  • clean-build-publicnpm run clean-build
  • depcheckdepcheck
  • developwebpack --watch --config=webpack.config.js
  • escheckes-check --module es5 dist/*.js
  • generate-declarationstsc -p tsconfig.declarations.json
  • generate-docsnode ./tools/docs/generate.mjs
  • linteslint
  • lint:fixeslint --fix
  • lint:prettierprettier "**/*.+(ts|tsx|json|js|mjs|yml|yaml|md)" --check
  • lint:prettier:fixprettier "**/*.+(ts|tsx|json|js|mjs|yml|yaml|md)" --write
  • testenv NODE_ENV=test mocha --config .mocha/default.js
  • test:coveragenpm run test:coverage:runtime && npm run test:coverage:types
  • test:coverage:runtimeenv NODE_ENV=test c8 mocha --config .mocha/transpile-only.js
  • test:coverage:typestsc --noEmit -p tsconfig.json