Package evidence
@times-components/article-comments@0.57.86-08aad5bf3758e1ac0dbd3f3365398abf6ca101aa.1
no findings
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 4,585Niche · −30% score
- Versions published
- 1,419Mature · −50% score
- First published
- Nov 2018
- Publisher
- news-tools
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@times-components/article-comments@0.57.86-08aad5bf3758e1ac0dbd3f3365398abf6ca101aa.1"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@times-components/article-comments@0.57.86-08aad5bf3758e1ac0dbd3f3365398abf6ca101aa.1"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts12
bundleNODE_ENV=production webpack -pcleanup-distrm -rf distdepcheckdepcheck --ignores='@babel/*,babel-*,depcheck,eslint,jest,prettier,webpack*' --ignore-bin-package=false --skip-missingfix:prettierprettier --write '**/*.{js,json}'fmteslint . --fix && prettier --write '**/*.*'linteslint . && yarn prettier:diff && yarn depcheckprepublishOnlyyarn transpile && yarn bundleprettier:diffprettier --list-different '**/*.*'test:webjest --config='./__tests__/jest.config.js'test:web:updatesnapshotyarn test:web -utranspileyarn cleanup-dist && babel src -d distwatchwatch 'yarn bundle' ./src --ignoreDotFiles --ignoreUnreadable
Dependencies8
@times-components/link^3.18.47@times-components/tracking^2.27.22@times-components/ts-components^1.188.1-08aad5bf3758e1ac0dbd3f3365398abf6ca101aa.1+08aad5bf37@times-components/ts-styleguide^1.56.41@times-components/user-state^0.7.49@times-components/utils^6.45.0prop-types15.7.2styled-components4.3.2