Package evidence
[email protected]
Remote Dependency Spec: devDependencies.starknet_specs="github:starkware-libs/starknet-specs#v0.9.0"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 185,326Ubiquitous · −70% score
- Versions published
- 310Mature · −50% score
- First published
- Oct 2021
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Dependency Spec: devDependencies.starknet_specs="github:starkware-libs/starknet-specs#v0.9.0"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 4 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Dependency Spec | package.json | devDependencies.starknet_specs="github:starkware-libs/starknet-specs#v0.9.0" | 8 |
| medium | Remote Dependency Spec | package.json | devDependencies.starknet_specs_08="github:starkware-libs/starknet-specs#v0.8.1" | 8 |
Manifest
Package metadata
Scripts20
buildtsup && npm run build:esm && npm run build:iife && npm run build:dtsbuild:dtstsup --clean false --dts-onlybuild:esmtsup --clean false --format esm --platform nodebuild:iifetsup --clean false --format iife --platform browserdocscd www && npm run startdocs:buildcd www && GIT_REVISION_OVERRIDE=${npm_config_git_revision_override} npm run builddocs:build:versionv=$(npm run info:version -s) && npm run docs:build --git-revision-override=${npm_config_git_revision_override=v$v}docs:versionv=$(npm run info:version -s) && cd www && npm run version ${npm_config_version_override=$v}formatprettier --log-level log --write "**/*.{ts,js,md,yml,json}"info:versionnpm pkg get version | xargslinteslint . --cache --fix --ext .tsposttestnpm run format -- --log-level warnpreparenpm run build && huskypretestnpm run lint && npm run ts:checktestjest -i --detectOpenHandlestest:coveragejest -i --coveragetest:watchjest --watchts:checktsc --noEmit --resolveJsonModule --project tsconfig.eslint.jsonts:coveragetype-coverage --at-least 95ts:coverage:reporttypescript-coverage-report
Dependencies10
@noble/curves~1.7.0@noble/hashes~1.6.0@scure/base~1.2.1@scure/starknet1.1.0@starknet-io/get-starknet-wallet-standard^5.0.0@starknet-io/starknet-types-0101npm:@starknet-io/[email protected]@starknet-io/starknet-types-0103npm:@starknet-io/[email protected]@starknet-io/starknet-types-09npm:@starknet-io/types-js@~0.9.2abi-wan-kanabi2.2.4lossless-json^4.2.0