PkgRadar

Package evidence

@vertigis/[email protected]

Remote Dependency Spec: dependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
1,038Niche · −30% score
Versions published
417Mature · −50% score
First published
Apr 2020
Publisher
vertigis-sa

Effective trust discount applied: 50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@vertigis/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@vertigis/[email protected]"],"fail_on":"review"}'
Publishervertigis-sa
Artifact bytes3,642,704
Previous version53.16.0
Published2026-06-01T21:37:41.484Z
SHA-256df8f07f019b4bfabb5cd1f8997494976bc2a83e91fd73f6c935341cada141d20

Why flagged

What the scanner saw

Remote Dependency Spec: dependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz"

1 remote tarball(s) were followed statically.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
3Score
53.16.1Version
Status history (1 event)
  1. newavailable · risk review · score 3 · status changed

Evidence

Static findings

1 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highRemote Dependency Specpackage.jsondependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz"12

Remote payloads

Followed remote artifacts

SourceURLRiskScoreSummary
dependencies.xlsxhttps://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgzlow0no remote findings

Manifest

Package metadata

Scripts16
  • app-schemanode build/js/appSchema.js
  • auditnpx --yes audit-ci@^6 --config ./audit-ci.jsonc
  • buildnpm run -s cleanup-build && npm run -s copy-static-files && tsc -p src/tsconfig.bundle.json && tsc-strict -p src/tsconfig.bundle.json && npm run -s minify && npm run -s docs && npm run -s app-schema
  • build-debugnpm run -s cleanup-build && npm run -s copy-static-files && tsc -p src/tsconfig.bundle.json && tsc-strict -p src/tsconfig.bundle.json
  • cleanup-builddel-cli *.js *.js.map *.d.ts "!jest.config.js" "!eslint.config.js" data forked-libs layer-preset locale mapping menus portal printing reports support tasks tests utilities workflow
  • copy-static-filescpx "src/**/*.{js,d.ts}" "./"
  • docstypedoc
  • initializedel-cli build/js && tsc -p build && node build/js/postInstall.js
  • linteslint --max-warnings=0 ./src
  • minifynode build/js/minify.js
  • preparein-install && npm run -s initialize || not-in-install
  • prettierprettier --write "**/*.ts" "**/*.json" "**/*.js"
  • startnpm run -s cleanup-build && npm run -s copy-static-files && tsc -w -p src/tsconfig.bundle.json
  • testtsc -p ./src/tsconfig.test.json && cross-env TZ="America/Los_Angeles" NODE_OPTIONS="--max-old-space-size=4096 --experimental-vm-modules" jest --maxWorkers=50% --workerIdleMemoryLimit=800MB
  • test-watchnpm run test -- --watch
  • watch-build-foldertsc -p build -w
Dependencies10
  • alasql~4.5.2
  • dxf-parser^1.1.2
  • elasticlunr~0.9.5
  • esri-proj-codes~1.0.3
  • jszip~3.10.1
  • luxon~3.5.0
  • safe-stable-stringify^2.5.0
  • shpjs~4.0.2
  • ts-essentials10.0.3
  • xlsxhttps://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz