Package evidence
@zkp2p/[email protected]
Remote Dependency Spec: dependencies.@reclaimprotocol/tls="github:reclaimprotocol/tls"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 21
- Versions published
- 18Established · −30% score
- First published
- Aug 2024
- Publisher
- richardliang
Effective trust discount applied: −30% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@zkp2p/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@zkp2p/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Dependency Spec: dependencies.@reclaimprotocol/tls="github:reclaimprotocol/tls"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 14 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Dependency Spec | package.json | dependencies.@reclaimprotocol/tls="github:reclaimprotocol/tls" | 12 |
| medium | Remote Dependency Spec | package.json | devDependencies.@adiwajshing/eslint-config="github:adiwajshing/eslint-config" | 8 |
Manifest
Package metadata
Scripts28
buildtsc -p tsconfig.build.json && tsc-aliasbuild-contractscd avs/contracts && forge buildbuild:browsersh ./src/scripts/build-browser.shcheck:avs-registrationnpm run run:tsc -- src/scripts/check-avs-registration.tscommitlintcommitlint --editcreate:claimnpm run run:tsc -- src/scripts/generate-receipt.tsdeploy:contractssh avs/utils/anvil/deploy-all-to-anvil-and-save-state.shdeploy:contracts-to-chainsh avs/utils/anvil/deploy-to-chain.shdownload:zk-filesnode node_modules/@reclaimprotocol/zk-symmetric-crypto/lib/scripts/download-filesgenerate:avstypechain -- --target ethers-v5 --out-dir src/avs/contracts avs/contracts/out/ReclaimServiceManager.sol/*.jsongenerate:contracts-datash ./src/scripts/contract-data-gen.shgenerate:protosh ./src/scripts/generate-proto.shgenerate:provider-typesnpm run run:tsc -- src/scripts/generate-provider-types.tsgenerate:toprf-keysnpm run run:tsc -- src/scripts/generate-toprf-keys.tslinteslint ./ --ext .js,.ts,.jsx,.tsxlint:fixeslint ./ --fix --ext .js,.ts,.jsx,.tsxpreparesh ./src/scripts/prepare.shpublish:pkgnpm publish --access publicregister:avs-operatornpm run run:tsc -- src/scripts/register-avs-operator.tsrun:tscSWC_NODE_IGNORE_DYNAMIC=true node -r @swc-node/registerstartnode lib/scripts/start-serverstart:chainbash ./avs/utils/anvil/start-anvil-chain-with-el-and-avs-deployed.shstart:tscnpm run run:tsc -- src/scripts/start-servertestNODE_ENV=test TZ=utc jest --verbose --forceExit --detectOpenHandlestest:avsNODE_ENV=test TZ=utc jest --verbose --forceExit --detectOpenHandles --test-match **/src/avs/tests/test.*.tsupdate:avs-metadatanpm run run:tsc -- src/scripts/update-avs-metadata.tsverify:root-canpm run run:tsc -- src/scripts/verify-root-ca.tswhitelist:operatornpm run run:tsc -- src/scripts/whitelist-operator.ts
Dependencies22
@bufbuild/protobuf^2.2.2@commitlint/cli^17.8.1@commitlint/config-conventional^17.8.1@reclaimprotocol/tlsgithub:reclaimprotocol/tls@reclaimprotocol/zk-symmetric-crypto^3.0.5ajv^8.17.1canonicalize^2.0.0dotenv^16.4.6elastic-apm-node^4.8.1esprima-next^5.8.4ethers^5.7.2https-proxy-agent^7.0.5ip-cidr^3.0.0jsdom^24.1.3jsonpath-plus^10.2.0p-queue^6.6.2pino^9.5.0protobufjs^7.4.0re2^1.21.4serve-static^1.16.2snarkjs^0.7.5ws^8.18.0
Optional dependencies1
koffi^2.9.2