Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 2
- Versions published
- 1
- First published
- Jul 2025
- Publisher
- alexstolr-tres
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@tres-finance/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@tres-finance/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Payload: matched "raw.githubusercontent.com"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 12 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/src/plugins/sanctum/lstsPricingJob.ts | matched "raw.githubusercontent.com" | 12 |
Manifest
Package metadata
Dependencies39
@aave/contract-helpers^1.28.2@aave/math-utils^1.28.2@aptos-labs/ts-sdk^1.19.0@bonfida/spl-name-service^3.0.8@cosmjs/cosmwasm-stargate^0.31.1@drift-labs/sdk^2.124.0-beta.0@drift-labs/vaults-sdk^0.9.8@ethersproject/bignumber^5.7.0@ethersproject/constants^5.7.0@ethersproject/providers^5.7.2@ethersproject/units^5.7.0@isaacs/ttlcache^1.4.1@metaplex-foundation/beet^0.7.1@metaplex-foundation/beet-solana^0.4.0@mysten/bcs^0.11.1@mysten/sui^1.12.0@onsol/tldparser^0.6.1@project-serum/anchor^0.26.0@sei-js/core^3.2.1@sei-js/proto^3.1.0@solana/spl-token^0.4.13@solana/web3.js^1.98.0@tres-finance/tx-parser^1.2.11axios^1.7.9bignumber.js^9.1.2bn.js^5.2.1buffer6.0.1decimal.js^10.4.3dsa-connect^0.6.47ethers^5.7.2- …and 9 more.