Package evidence
@telicent-oss/[email protected]
Install-time lifecycle script: postinstall="[ \"$LOCAL_MACHINE\" = \"false\" ] && echo 'Skipping tefe hook-postinstall' || tefe hook-postinstall"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 144
- Versions published
- 202Mature · −50% score
- First published
- Mar 2024
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@telicent-oss/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@telicent-oss/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Install-time lifecycle script: postinstall="[ \"$LOCAL_MACHINE\" = \"false\" ] && echo 'Skipping tefe hook-postinstall' || tefe hook-postinstall"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 1 · status changed
Evidence
Static findings
3 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 3 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Install-time lifecycle script | package.json | postinstall="[ \"$LOCAL_MACHINE\" = \"false\" ] && echo 'Skipping tefe hook-postinstall' || tefe hook-postinstall" | 5 |
| low | Large Javascript Payload | package/dist/ds.umd.cjs | 7442120 bytes | 0 |
| low | Large Javascript Payload | package/dist/ds.js | 7093689 bytes | 0 |
Manifest
Package metadata
Scripts30
buildvite buildbuild-storybookstorybook buildbuild-storybook-docsstorybook build --docsbump:preyarn bump:prereleasebump:prereleaseyarn version --prerelease && git push && git push --tagscheck./.husky/pre-commitchromaticchromatic --exit-zero-on-changescleanrimraf dist storybook-staticcssnpx tailwindcss -i ./src/index.css -o ./src/main.cssejectreact-scripts ejectgit-checks./.husky/pre-commit && ./.husky/pre-pushgit-hooksyarn git-checkslink-to-local-packages./scripts/link-to-local-packages.shlinteslint --resolve-plugins-relative-to srclocal-installyarn install --registry http://localhost:4873local-publish./scripts/local-publish.shlpyarn local-publishpostinstall[ "$LOCAL_MACHINE" = "false" ] && echo 'Skipping tefe hook-postinstall' || tefe hook-postinstallpostlocal-publish./scripts/update-deps.mjs --file ./updateDeps.gitignored.jsonprebuildyarn cleanpreparehusky installprestartyarn run csspreviewvite previewstartvitestorybookstorybook dev -p 6006storybook-docsstorybook dev --docs --no-manager-cachetestreact-scripts testtest:ciyarn test --ci --json --outputFile="results.json" --watchAll=falsetest:diffreact-scripts test --watchAll=false --coverage=false --onlyChanged --bailtest:diffMainreact-scripts test --watchAll=false --coverage=false --changedSince=origin/main --bail
Dependencies31
@emotion/react^11.10.6@emotion/styled^11.10.6@fortawesome/fontawesome-svg-core^6.5.1@fortawesome/free-regular-svg-icons^6.5.1@fortawesome/free-solid-svg-icons^6.5.1@fortawesome/react-fontawesome^0.2.0@mui/lab5.0.0-alpha.170@mui/material^5.16.6@mui/x-date-pickers^8.9.2@react-spring/web9.7.3@telicent-oss/fe-auth-lib1.0.3@telicent-oss/mui-icons-material^1.0.0@telicent-oss/react-lib^0.5.0@telicent-oss/telicent-frontend-cli^1.5.0@types/lodash.debounce^4.0.9classnames^2.3.1d3^7.8.2dayjs^1.11.13gsap^3.13.0lodash^4.17.21lodash.debounce^4.0.8lodash.merge^4.6.2maplibre-gl^3.5.0ol^10.7.0ol-mapbox-style^12.6.1react-error-boundary^5.0.0react-map-gl^7.1.6react-rnd^10.4.13react-router-dom^6.23.1svg-path-parser^1.1.0- …and 1 more.