Package evidence
@woovi/[email protected]
Remote Dependency Spec: dependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.0/xlsx-0.20.0.tgz"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 147
- Versions published
- 107Mature · −50% score
- First published
- Sep 2023
- Publisher
- yumartins
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@woovi/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@woovi/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Dependency Spec: dependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.0/xlsx-0.20.0.tgz"
1 remote tarball(s) were followed statically.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 6 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Remote Dependency Spec | package.json | dependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.0/xlsx-0.20.0.tgz" | 12 |
Remote payloads
Followed remote artifacts
| Source | URL | Risk | Score | Summary |
|---|---|---|---|---|
| dependencies.xlsx | https://cdn.sheetjs.com/xlsx-0.20.0/xlsx-0.20.0.tgz | low | 0 | no remote findings |
Manifest
Package metadata
Scripts27
buildturbo run lib:prodchangelo:majorpnpm n ./scripts/release/changelog.ts --majorchangelo:minorpnpm n ./scripts/release/changelog.ts --minorchangelo:patchpnpm n ./scripts/release/changelog.ts --patchcheck:updatesbunx npm-check-updates --interactive --format groupdocs:buildstorybook builddocs:devstorybook dev -p 6006firstReleasewoovi-first-releasei18npnpm i18n:scan && pnpm i18n:translatei18n:scanpnpm n scripts/i18next-parser/i18next-parser.jsi18n:translatepnpm zx scripts/i18next-parser/translateI18n.mjs ./locales/pt-BR.json -no-autolib:devNODE_OPTIONS='--max-old-space-size=8192' DEBUG=rsbuild rslib build --watchlib:prodNODE_OPTIONS='--max-old-space-size=8192' rslib buildlintturbo run lint:eslintlint:biomebunx biome check --write ./src && bunx biome format --write ./srclint:eslinteslint .mergePullRequestReleasewoovi-merge-pr-releasennode --experimental-strip-typesrelease:majorwoovi-changelog --majorrelease:minorwoovi-changelog --minorrelease:patchwoovi-changelog --patchstorybookturbo run docs:devstorybook:buildturbo run docs:buildtypecheckturbo run typecheck:tsgotypecheck:tsctsc -p ./tsconfig.json --noEmit --emitDeclarationOnly falsetypecheck:tsgotsgo -p ./tsconfig.tsgo.json --noEmitupdateReleasewoovi-update-release
Dependencies37
@emotion/react^11.14.0@emotion/styled^11.14.1@mui/icons-material7.3.8@mui/lab7.0.1-beta.22@mui/material7.3.8@mui/system^7.3.8@mui/x-data-grid-pro8.27.1@mui/x-license^8.26.0@tanstack/react-virtual3.13.18@woovi-private/release^1.1.0brazilian-values0.13.1dot-object2.1.5formik3.0.0-next.6i18next^23.16.5i18next-browser-languagedetector8.2.1libphonenumber-js1.12.36lodash^4.17.21mime-types3.0.2moment2.30.1notistack2.0.8qrcode.react4.2.0query-string9.3.1react-code-blocks0.1.6react-dropzone14.4.0react-error-boundary6.1.0react-i18next15.7.4react-relay20.1.1react-rnd10.5.2react-virtual2.2.5react-window1.8.10- …and 7 more.