Development always based on production and add "-beta.version" in behind. Every deployment from development to production will increment based on semantic versioninig.
Install invokes pnpm in ../package, outside the installed package directory. This can alter that sibling project's dependency state; no confirmed malicious payload or data exfiltration was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a high-severity secret pattern.
dist/assets-DiH3EaF3.jsView on unpkg · L85Package contains source files above the static scanner size ceiling.
dist/DocumentViewer.vue_vue_type_script_setup_true_lang-jTkg_too.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L97Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L97Package contains a high-severity secret pattern.
dist/assets-DiH3EaF3.jsView on unpkg · L85Package contains source files above the static scanner size ceiling.
dist/DocumentViewer.vue_vue_type_script_setup_true_lang-jTkg_too.jsView on unpkg