PkgRadar

Package evidence

@skbkontur/[email protected]

no findings

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
55
Versions published
86Mature · −50% score
First published
Sep 2020
Publisher
skbkontur-bot

Effective trust discount applied: 50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Looks clean — keep monitoring

No high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@skbkontur/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@skbkontur/[email protected]"],"fail_on":"review"}'
Publisherskbkontur-bot
Artifact bytes67,823
Previous version3.4.4
Published2025-06-18T11:33:55.458Z
SHA-25685fa1fa3d5bb4b52bdd6b5caf36fcd0afaaef4cecdae8ac758889a746742bdd0

Why flagged

What the scanner saw

No high-signal static finding in the saved report.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

low
Last checked
lowRisk
0Score
3.4.8Version
Status history (1 event)
  1. newavailable · risk low · score 0 · status changed

Evidence

Static findings

No findings stored for this release.

Manifest

Package metadata

Scripts15
  • buildrun-s build:types build:clean build:tsc "build:copy:*" build:patch build:pack
  • build:cleanrimraf dist
  • build:copy:metacopyfiles --flat package.json "../*.md" ../LICENSE dist
  • build:copy:srccopyfiles --up 1 "src/**/*.js" dist
  • build:packcd dist && npm pack
  • build:patchnode ./patch-version
  • build:tsctsc --project tsconfig.prod.json
  • build:typesdotnet ts-gen --assembly ./../Cassandra.DistributedTaskQueue.Monitoring.TestService/bin/net6.0/SkbKontur.Cassandra.DistributedTaskQueue.Monitoring.TestService.dll --outputDir ./src/Domain/Api --nullabilityMode Pessimistic
  • lintrun-s "lint:*"
  • lint:eslinteslint ./ --ext .js,.jsx,.ts,.tsx --cache --quiet
  • lint:tsctsc --noEmit
  • startvite --mode dev
  • start:prodvite
  • storybooksb dev -p 6006
  • testvitest --run --reporter dot
Dependencies8
  • @skbkontur/edi-ui^0.4.0
  • @skbkontur/react-stack-layout^1.0.3
  • date-fns^3.6.0
  • decimal.js^10.2.1
  • lodash^4.17.21
  • qs^6.11.2
  • tslib^2.4.0
  • whatwg-fetch^3.5.0