Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 318
- Versions published
- 251Mature · −50% score
- First published
- Jul 2018
- Publisher
- ajo2995
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Payload: matched "curl "
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 9 · status changed
Evidence
Static findings
3 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/.claude/settings.local.json | matched "curl " | 12 |
| medium | Large Javascript Payload | package/src/static/jbrowse2.umd.dev.js | 19128141 bytes | 10 |
| medium | Large Javascript Payload | package/sorghum/sorghum.4d3065de.js | 8721207 bytes | 10 |
Manifest
Package metadata
Scripts13
buildparcel buildbuild-grapevineSUBSITE=grapevine parcel build --no-scope-hoist --dist-dir grapevine src/grapevine.html && mv grapevine/grapevine.html grapevine/index.htmlbuild-mainSUBSITE=main parcel build --no-scope-hoist --dist-dir main src/index.htmlbuild-maizeSUBSITE=maize parcel build --no-scope-hoist --dist-dir maize src/maize.html && mv maize/maize.html maize/index.htmlbuild-riceSUBSITE=rice parcel build --no-scope-hoist --dist-dir rice src/rice.html && mv rice/rice.html rice/index.htmlbuild-sorghumSUBSITE=sorghum parcel build --no-scope-hoist --dist-dir sorghum src/sorghum.html && mv sorghum/sorghum.html sorghum/index.htmlpreparenpx parcel buildstart-grapevineSUBSITE=grapevine parcel src/grapevine.htmlstart-mainSUBSITE=main parcel src/index.htmlstart-maizeSUBSITE=maize parcel src/maize.htmlstart-riceSUBSITE=rice parcel src/rice.htmlstart-sorghumSUBSITE=sorghum parcel src/sorghum.htmlwatchparcel watch
Dependencies34
@fortawesome/fontawesome-free^6.6.0@parcel/watcher^2.5.1ag-grid-community^31.1.1ag-grid-react^31.0.3axios^1.6.8d3^7.9.0firebase^11.0.1flat-to-nested^1.1.1gramene-bins-client^2.3.3gramene-dbxrefs^3.0.15gramene-efp-browser^1.0.11gramene-genetree-vis^4.2.11gramene-mdview^2.0.8gramene-search-vis^4.2.5gramene-taxonomy-with-genomes^3.0.10gramene-trees-client^2.6.1lodash^4.17.15lodash-compat^3.10.2money-clip^3.0.2numeral^2.0.6querystringify^2.2.0react^18.3.0react-bootstrap^2.7.2react-debounce-input^3.2.5react-dom^18.3.0react-ga4^2.1.0react-icons^4.3.1react-markdown^5.0.3react-router-dom^5.3.0react-simple-tree-menu^1.1.18- …and 4 more.