Package evidence
@trusted-american/[email protected]
Remote Dependency Spec: devDependencies.ember-code-snippet="github:ef4/ember-code-snippet"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 7
- First published
- Dec 2025
- Publisher
- charlesfries
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@trusted-american/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@trusted-american/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Dependency Spec: devDependencies.ember-code-snippet="github:ef4/ember-code-snippet"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 8 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Dependency Spec | package.json | devDependencies.ember-code-snippet="github:ef4/ember-code-snippet" | 8 |
Manifest
Package metadata
Scripts16
buildember build --environment=productionformatprettier . --cache --writelintconcurrently "pnpm:lint:*(!fix)" --names "lint:" --prefixColors autolint:cssstylelint "**/*.css"lint:css:fixconcurrently "pnpm:lint:css -- --fix"lint:fixconcurrently "pnpm:lint:*:fix" --names "fix:" --prefixColors auto && pnpm formatlint:formatprettier . --cache --checklint:hbsember-template-lint .lint:hbs:fixember-template-lint . --fixlint:jseslint . --cachelint:js:fixeslint . --fixlint:typesember-tsc --noEmitstartember servetestconcurrently "pnpm:lint" "pnpm:test:*" --names "lint,test:" --prefixColors autotest:emberember testtest:ember-compatibilityember try:each
Dependencies33
@babel/core^7.28.5@fortawesome/ember-fontawesome^3.1.0@fortawesome/fontawesome-svg-core^7.1.0@fortawesome/free-brands-svg-icons^7.1.0@fortawesome/free-solid-svg-icons^7.1.0@fullcalendar/core^6.1.19@fullcalendar/daygrid^6.1.19@fullcalendar/list^6.1.19@fullcalendar/timegrid^6.1.19@github/markdown-toolbar-element^2.2.3@tiptap/core^3.14.0@tiptap/pm^3.14.0@tiptap/starter-kit^3.14.0@trusted-american/core^0.0.6@types/bootstrap^5.2.10bootstrap^5.3.7dayjs^1.11.19ember-auto-import^2.12.0ember-basic-dropdown^8.9.0ember-breadcrumb-trail^2.0.0ember-cli-babel^8.2.0ember-cli-htmlbars^7.0.0ember-cli-showdown^9.0.2ember-concurrency^5.1.0ember-file-upload^9.5.0ember-modifier^4.2.2ember-power-select^8.12.1ember-power-select-with-create^3.1.0ember-template-imports^4.3.0ember-truth-helpers^5.0.0- …and 3 more.