Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 1,506Mature · −50% score
- First published
- Jun 2025
- Publisher
- superblocksteam-admin
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@superblocksteam/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@superblocksteam/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts13
buildMODE=production tsdownchecknpm run typecheck && npm run lintcleanpremove dist* tsconfig.tsbuildinfodevMODE=local-dev tsdown --watch --no-cleankebabify./scripts/kebabify.tslinteslint --max-warnings 0 --concurrency=2lint:fixeslint --fix --concurrency=2previewvite previewpublish-packagepnpm publishtestvitest runtest:relatedvitest related --run $(git diff --cached --name-only --relative)test:watchvitest --uitypechecktsc --build --noEmit
Dependencies38
@dagrejs/graphlib2.2.4@oddbird/css-anchor-positioning^0.4.0@opentelemetry/api^1.9.1@opentelemetry/api-logs^0.214.0@opentelemetry/core^2.6.1@opentelemetry/exporter-logs-otlp-http^0.214.0@opentelemetry/exporter-trace-otlp-http^0.214.0@opentelemetry/resources^2.6.1@opentelemetry/sdk-logs^0.214.0@opentelemetry/sdk-trace-base^2.6.1@opentelemetry/sdk-trace-web^2.6.1@opentelemetry/semantic-conventions^1.36.0@radix-ui/react-dialog^1.1.6@superblocksteam/fast-deep-equal3.1.4@superblocksteam/iso-currency^3.0.0@superblocksteam/library-shared2.0.128@superblocksteam/sdk-api2.0.128@superblocksteam/shared0.9590.8hotkeys-js^3.8.3lodash^4.17.21microdiff^1.5.0mobx6.13.6mobx-react-lite4.1.0modern-screenshot^4.6.7moment2.29.4moment-timezone0.5.46normalize.css8.0.1postcss^8.5.6posthog-js^1.258.3react-dnd^16.0.1- …and 8 more.