Web
A user-initiated publish sends an npm bearer token and uploaded package contents to an author-controlled Worker. The Worker can capture both before optionally proxying to npm.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe app stores the entered npm token in browser local storage.
app.jsView on unpkg · L6The Worker-bound request includes the npm bearer token and all uploaded package attachments.
app.jsView on unpkg · L172The browser path sends publishing requests through an author-controlled Worker endpoint rather than directly to npm.
app.jsView on unpkg · L149This report applies to @vbansal67/npm-official-publisher@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe app stores the entered npm token in browser local storage.
app.jsView on unpkg · L6The Worker-bound request includes the npm bearer token and all uploaded package attachments.
app.jsView on unpkg · L172The browser path sends publishing requests through an author-controlled Worker endpoint rather than directly to npm.
app.jsView on unpkg · L149