Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 2
- First published
- Jun 2026
- Publisher
- carlosfmontero
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts47
adaptnode tools/adapt-spec-pack.mjscoveragec8 npm testcrawlnode tools/crawl-repo.mjsdevnode server/index.mjsdriftnode tools/detect-drift.mjsdrift:profilesnode tools/drift-profiles.mjsfetch-livenode tools/fetch-live-pack.mjsfetch-validatorsnode tools/fetch-validators.mjslinteslint .lint:adapternode --check tools/adapt-spec-pack.mjs && node --check tools/lib/adapter.mjs && node --check tools/lib/mini-yaml.mjs && node --check tools/lib/promql.mjs && node --check tools/lib/promql-lezer.mjs && node --check tools/lib/traceability.mjs && node --check tools/lib/traceability-graph.mjs && node --check tools/lib/promql-canon.mjslint:clinode --check tools/cli.mjslint:crawlernode --check tools/crawl-repo.mjs && node --check tools/lib/crawler.mjslint:driftnode --check tools/detect-drift.mjslint:fetchernode --check tools/fetch-live-pack.mjslint:servernode --check server/index.mjslint:studionode --check studio/app.mjslint:zipnode --check tools/lib/zip.mjsservenode server/index.mjsstartnode server/index.mjssync-specnode tools/sync-spec.mjssync-spec:checknode tools/sync-spec.mjs --checktestnode --test tools/test-adapt.mjs tools/test-backend-validate.mjs tools/test-compile.mjs tools/test-crawl.mjs tools/test-diagnostic-grade.mjs tools/test-diff.mjs tools/test-fetch-live.mjs tools/test-golden-crawl.mjs tools/test-journey.mjs tools/test-packs.mjs tools/test-profiles.mjs tools/test-promql.mjs tools/test-promql-canon.mjs tools/test-retrofeed.mjs tools/test-traceability-graph.mjs tools/test-verify-deploy.mjs tools/test-zip.mjs server/test-workspace.mjs server/test-smoke.mjstest:adaptnode tools/test-adapt.mjstest:backendnode tools/test-backend-validate.mjstest:backend:livenode tools/test-backend-live.mjstest:backend:live:strictnode tools/test-backend-live.mjs --stricttest:backend:strictnode tools/test-backend-validate.mjs --stricttest:compilenode tools/test-compile.mjstest:crawlnode tools/test-crawl.mjstest:diagnosticnode tools/test-diagnostic-grade.mjs- …and 17 more.
Dependencies5
@lezer/highlight^1.2.3@lezer/lr^1.4.10@prometheus-io/lezer-promql^0.312.0-rc.0express^5.0.0openid-client^6.8.4