Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 434Mature · −50% score
- First published
- Mar 2018
- Publisher
- snyk-admin
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts14
buildtscbuild-watchtsc -wdebugtsc-watch --project tsconfig.json --onSuccess 'node --inspect --inspect-brk .'formatprettier --loglevel warn --write '{lib,test}/**/*.ts' && tslint --fix --format stylish '{lib,test}/**/*.ts'lintrun-p --max-parallel=${JOBS:-5} --aggregate-output lint:*lint:commitcommitlint --from=HEAD~1lint:prettierprettier --check "{lib,test}/**/*.ts"lint:tslinttslint --format stylish "{lib,test}/**/*.ts"preparenpm run buildtestnpm run test-jesttest-jestjest --ci --maxWorkers=3 --logHeapUsage --colorstest-jest-windowsjest --ci --maxWorkers=3 --config test/windows/jest.config.js --logHeapUsagetest:systemjest --ci --maxWorkers=3 --logHeapUsage --colors --testPathPattern='test/system/'test:unitjest --ci --maxWorkers=3 --logHeapUsage --colors --testPathPattern='test/(lib|unit)/'
Dependencies25
@snyk/composer-lockfile-parser^1.4.1@snyk/dep-graph^2.12.1@snyk/docker-registry-v2-client^2.24.2@snyk/rpm-parser^3.4.1@snyk/snyk-docker-pull^3.15.1@swimlane/docker-reference^2.0.1adm-zip^0.5.17chalk^2.4.2debug^4.4.3docker-modem^3.0.8dockerfile-ast^0.7.1elfy^1.0.0event-loop-spinner^2.3.2fzstd^0.1.1gunzip-maybe^1.4.2minimatch^9.0.0packageurl-js1.2.0semver^7.7.3shescape^2.1.7snyk-nodejs-lockfile-parser^2.7.0snyk-poetry-lockfile-parser1.9.1snyk-resolve-deps^4.9.1tar-stream^2.2.0tslib^1varint^6.0.0