Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 2,164Niche · −30% score
- Versions published
- 309Mature · −50% score
- First published
- May 2023
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 2917690 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 6 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/dist/index-DvA5z2ri.cjs | 2917690 bytes | 10 |
| medium | Large Javascript Payload | package/dist/index-BBfAOswk.js | 3919720 bytes | 10 |
Manifest
Package metadata
Scripts19
buildvite buildbuild:libBUILD_TARGET=lib vite buildcheckTstsc --noEmitcleanAndSetuptsx ./internals/scripts/clean.tseslinteslint --ext js,ts,tsxextract-messagesi18next-scanner --config=internals/extractMessages/i18next-scanner.config.jsgeneratetsx ./node_modules/plop/bin/plop.js --plopfile internals/generators/plopfile.tslintyarn run eslint srclint:cssstylelint src/**/*.csslint:fixyarn run eslint --fix srcprepublishOnlyyarn run build:libprettifyprettier --writepreviewvite previewstartvitestart:prodyarn run build && vite previewtestvitest runtest:coveragevitest run --coveragetest:generatorstsx ./internals/testing/generators/test-generators.tstest:watchvitest
Dependencies38
@codemirror/lang-sql^6.4.0@codemirror/state^6.5.2@codemirror/view^6.39.11@reduxjs/toolkit1.8.5@uiw/codemirror-extensions-basic-setup4.21.12@uiw/codemirror-extensions-langs4.21.12@uiw/react-codemirror4.21.12codemirror^6.0.0cronstrue2.27.0dagre^0.8.5datajunction0.0.1-rc.0fontfaceobserver2.3.0formik2.4.3i18next21.9.2i18next-browser-languagedetector6.1.5js-cookie3.0.5react18.2.0react-cookie4.1.1react-diff-view3.2.1react-dom18.2.0react-helmet-async1.3.0react-i18next11.18.6react-is18.2.0react-markdown9.0.1react-querybuilder6.5.1react-redux7.2.8react-router-dom6.3.0react-select5.7.3react-syntax-highlighter^15.5.0reactflow^11.7.0- …and 8 more.
Optional dependencies4
@rollup/rollup-darwin-arm644.60.4@rollup/rollup-darwin-x644.60.4@rollup/rollup-linux-arm64-gnu4.60.4@rollup/rollup-linux-x64-gnu4.60.4