All @antv/g2plot versions

@antv/g2plot @2.5.35

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
100
Risk Score
License
Yes
Install Scripts
14
Dependencies
41
Dev Dependencies
2542.5 KB
Package Size
Published

Maintainers

lviseifreestyle21soundquietelaine.q.10sturubysakuya223serializedowenxdzhaoyangzhanmeiwjgogogoleungwensendoriiaaronyardsimaqdxq613intchoussusan_annjinke.lilzxuearmy8735atoolbaizndengfupingneoddishjeffy2012zqluafc163pomelo-nwukopiluwakyccnuzindexpanyuqibubkoozengyuekasmineboyu.zljl1ud0ngq1newbyvectorwinniexingchenlulikn9117xdddstsemious2020esoranadia_liubbsqqmxz96102openwaynepearminipddpdyiqianyaozhanbacxxxxxnlaixingui.lxgsusiwen8yanxiongzeyuwangrainy25ghzzhangjunjie-lokiflash1yisi.wangdreammy23biupiubiupiubasketduckxuying1027banxuanpearl_wangbqxbqxbqxalex_zjtduxinyue023wang1212leondt1gaofuhongxcf(-_-)boyyangzaisiqisheninterstellarmtmoayuisuda

Keywords

chartplotantv

Dependencies (14)

PackageConstraintRegistry Status
fmin ^0.0.2 auto_approved
tslib ^2.0.3 auto_approved
pdfast ^0.2.0 auto_approved
@antv/g2 ^4.2.12 No greenflagged match
@antv/util ^2.0.17 No greenflagged match
@antv/scale ^0.3.18 No greenflagged match
size-sensor ^1.0.1 auto_approved
@antv/g-base ^0.5.11 auto_approved
d3-hierarchy ^2.0.0 auto_approved
d3-regression ^1.3.5 auto_approved
@antv/path-util ^3.0.1 auto_approved
@antv/color-util ^2.0.6 auto_approved
@antv/matrix-util ^3.1.0-beta.2 No greenflagged match
@antv/event-emitter ^0.1.2 auto_approved

Dev Dependencies (41)

PackageConstraintRegistry Status
miz ^1.0.1 Not imported
antd ^4.8.4 No greenflagged match
jest ^26.0.1 auto_approved
husky ^4.2.3 auto_approved
react ^16.11.0 auto_approved
eslint ^8.35.0 auto_approved
rimraf ^3.0.0 auto_approved
ts-jest ^25.4.0 No greenflagged match
webpack ^4.44.2 auto_approved
prettier ^2.0.1 auto_approved
cross-env ^7.0.2 auto_approved
react-dom ^16.11.0 auto_approved
ts-loader ^7.0.0 No greenflagged match
limit-size ^0.1.3 Not imported
typescript ^4 auto_approved
@babel/core ^7.10.4 auto_approved
@types/jest ^25.2.1 No greenflagged match
lint-md-cli ^0.1.2 Not imported
lint-staged ^10.0.7 auto_approved
npm-run-all ^4.1.5 auto_approved
webpack-cli ^3.3.7 No greenflagged match
babel-loader ^8.1.0 No greenflagged match
jest-electron ^0.1.7 Not imported
jest-extended ^0.11.2 No greenflagged match
react-i18next ^11.7.0 No greenflagged match
@antv/data-set ^0.11.5 auto_approved
@babel/runtime ^7.11.2 auto_approved
@commitlint/cli ^8.2.0 No greenflagged match
@babel/preset-env ^7.10.4 auto_approved
generate-changelog ^1.8.0 auto_approved
webpack-dev-server ^3.9.0 No greenflagged match
eslint-plugin-import ^2.22.0 auto_approved
eslint-config-prettier ^8.7.0 auto_approved
eslint-plugin-prettier ^4.2.0 auto_approved
webpack-bundle-analyzer ^3.9.0 No greenflagged match
@typescript-eslint/parser ^5.54.1 auto_approved
@commitlint/config-angular ^8.2.0 No greenflagged match
conventional-changelog-cli ^2.0.34 auto_approved
jest-matcher-deep-close-to ^2.0.1 No greenflagged match
@babel/plugin-transform-runtime ^7.11.5 auto_approved
@typescript-eslint/eslint-plugin ^5.54.1 auto_approved

Transitive Dependency Tree

159 transitive deps max depth 10
  ├─ @antv/color-util ^2.0.6 → 2.0.6
  ├─ @antv/event-emitter ^0.1.2 → 0.1.3
  ├─ @antv/g-base ^0.5.11 → 0.5.16
  ├─ @antv/g2 ^4.2.12
  ├─ @antv/matrix-util ^3.1.0-beta.2
  ├─ @antv/path-util ^3.0.1 → 3.0.1
  ├─ @antv/scale ^0.3.18
  ├─ @antv/util ^2.0.17
  ├─ d3-hierarchy ^2.0.0 → 2.0.0
  ├─ d3-regression ^1.3.5 → 1.3.10
  ├─ fmin ^0.0.2 → 0.0.2
  ├─ pdfast ^0.2.0 → 0.2.0
  ├─ size-sensor ^1.0.1 → 1.0.3
├─ tslib ^2.0.3 → 2.8.1
  ├─ @antv/event-emitter ^0.1.1
  ├─ @antv/matrix-util ^3.1.0-beta.1
  ├─ @antv/path-util ~2.0.5
  ├─ @antv/util ^2.0.9
  ├─ @antv/util ~2.0.13
  ├─ @types/d3-timer ^2.0.0 → 2.0.3
  ├─ contour_plot ^0.0.1 → 0.0.1
  ├─ d3-ease ^1.0.5 → 1.0.7
  ├─ d3-interpolate ^3.0.1 → 3.0.1
  ├─ d3-timer ^1.0.9 → 1.0.10
  ├─ detect-browser ^5.1.0 → 5.3.0
  ├─ gl-matrix ^3.1.0 → 3.4.4
  ├─ json2module ^0.0.3 → 0.0.3
  ├─ lodash-es ^4.17.21 → 4.18.1
  ├─ rollup ^0.25.8 → 0.25.8
  ├─ tape ^4.5.1 → 4.17.0
  ├─ tslib ^2.0.3 → 2.8.1
├─ uglify-js ^2.6.2 → 2.8.29
  ├─ @ljharb/resumer ~0.0.1 → 0.0.1
  ├─ @ljharb/through ~2.3.9 → 2.3.14
  ├─ call-bind ~1.0.2 → 1.0.9
  ├─ chalk ^1.1.1 → 1.1.3
  ├─ d3-color 1 - 3 → 3.1.0
  ├─ deep-equal ~1.1.1 → 1.1.2
  ├─ defined ~1.0.1 → 1.0.1
  ├─ dotignore ~0.1.2 → 0.1.2
  ├─ for-each ~0.3.3 → 0.3.5
  ├─ glob ~7.2.3
  ├─ has ~1.0.3 → 1.0.4
  ├─ inherits ~2.0.4 → 2.0.4
  ├─ is-regex ~1.1.4
  ├─ minimist ^1.2.0 → 1.2.8
  ├─ minimist ~1.2.8 → 1.2.8
  ├─ mock-property ~1.0.0 → 1.0.2
  ├─ object-inspect ~1.12.3 → 1.12.3
  ├─ resolve ~1.22.6 → 1.22.11
  ├─ rw ^1.3.2 → 1.3.3
  ├─ source-map ~0.5.1 → 0.5.7
  ├─ source-map-support ^0.3.2 → 0.3.3
  ├─ string.prototype.trim ~1.2.8 → 1.2.10
  ├─ uglify-to-browserify ~1.0.0 → 1.0.2
├─ yargs ~3.10.0 → 3.10.0
  ├─ @ljharb/through ^2.3.9 → 2.3.14
  ├─ ansi-styles ^2.2.1 → 2.2.1
  ├─ call-bind ^1.0.8 → 1.0.9
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ call-bound ^1.0.2 → 1.0.4
  ├─ camelcase ^1.0.2 → 1.2.1
  ├─ cliui ^2.1.0 → 2.1.0
  ├─ decamelize ^1.0.0 → 1.2.0
  ├─ define-data-property ^1.1.4
  ├─ define-data-property ^1.1.0
  ├─ define-properties ^1.2.1 → 1.2.1
  ├─ es-abstract ^1.23.5 → 1.24.2
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-object-atoms ^1.0.0 → 1.1.2
  ├─ escape-string-regexp ^1.0.2 → 1.0.5
  ├─ functions-have-names ^1.2.3 → 1.2.3
  ├─ get-intrinsic ^1.3.0 → 1.3.1
  ├─ gopd ^1.0.1 → 1.2.0
  ├─ has ^1.0.3 → 1.0.4
  ├─ has-ansi ^2.0.0 → 2.0.0
  ├─ has-property-descriptors ^1.0.0 → 1.0.2
  ├─ has-property-descriptors ^1.0.2 → 1.0.2
  ├─ is-arguments ^1.1.1 → 1.2.0
  ├─ is-callable ^1.2.7 → 1.2.7
  ├─ is-core-module ^2.16.1 → 2.16.2
  ├─ is-date-object ^1.0.5 → 1.1.0
  ├─ is-regex ^1.1.4 → 1.2.1
  ├─ isarray ^2.0.5 → 2.0.5
  ├─ minimatch ^3.0.4 → 3.1.5
  ├─ object-is ^1.1.5 → 1.1.6
  ├─ object-keys ^1.1.1 → 1.1.1
  ├─ path-parse ^1.0.7 → 1.0.7
  ├─ regexp.prototype.flags ^1.5.1 → 1.5.4
  ├─ set-function-length ^1.2.2 → 1.2.2
  ├─ source-map 0.1.32 → 0.1.32
  ├─ strip-ansi ^3.0.0 → 3.0.1
  ├─ supports-color ^2.0.0 → 2.0.0
  ├─ supports-preserve-symlinks-flag ^1.0.0 → 1.0.0
├─ window-size 0.1.0 → 0.1.0
  ├─ amdefine >=0.0.4 → 1.0.1
  ├─ ansi-regex ^2.0.0 → 2.1.1
  ├─ array-buffer-byte-length ^1.0.2 → 1.0.2
  ├─ arraybuffer.prototype.slice ^1.0.4 → 1.0.4
  ├─ async-function ^1.0.0
  ├─ async-generator-function ^1.0.0 → 1.0.0
  ├─ available-typed-arrays ^1.0.7 → 1.0.7
  ├─ brace-expansion ^1.1.7 → 1.1.15
  ├─ call-bind ^1.0.8 → 1.0.9
  ├─ call-bind ^1.0.7 → 1.0.9
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ call-bound ^1.0.2 → 1.0.4
  ├─ call-bound ^1.0.4 → 1.0.4
  ├─ center-align ^0.1.1 → 0.1.3
  ├─ data-view-buffer ^1.0.2 → 1.0.2
  ├─ data-view-byte-length ^1.0.2 → 1.0.2
  ├─ data-view-byte-offset ^1.0.1 → 1.0.1
  ├─ define-data-property ^1.0.1
  ├─ define-data-property ^1.1.4
  ├─ define-properties ^1.2.1 → 1.2.1
  ├─ es-define-property ^1.0.0 → 1.0.1
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ es-object-atoms ^1.1.1 → 1.1.2
  ├─ es-set-tostringtag ^2.1.0 → 2.1.0
  ├─ es-to-primitive ^1.3.0 → 1.3.0
  ├─ function-bind ^1.1.2 → 1.1.2
  ├─ function.prototype.name ^1.1.8 → 1.1.8
  ├─ generator-function ^2.0.0 → 2.0.1
  ├─ get-intrinsic ^1.3.0 → 1.3.1
  ├─ get-intrinsic ^1.2.4 → 1.3.1
  ├─ get-proto ^1.0.1 → 1.0.1
  ├─ get-proto ^1.0.1
  ├─ get-symbol-description ^1.1.0
  ├─ globalthis ^1.0.4 → 1.0.4
  ├─ gopd ^1.0.1 → 1.2.0
  ├─ gopd ^1.2.0 → 1.2.0
  ├─ has-property-descriptors ^1.0.2 → 1.0.2
  ├─ has-property-descriptors ^1.0.0 → 1.0.2
  ├─ has-proto ^1.2.0
  ├─ has-symbols ^1.1.0 → 1.1.0
  ├─ has-tostringtag ^1.0.2 → 1.0.2
  ├─ hasown ^2.0.2 → 2.0.4
  ├─ hasown ^2.0.3 → 2.0.4
  ├─ internal-slot ^1.1.0
  ├─ is-array-buffer ^3.0.5
  ├─ is-callable ^1.2.7 → 1.2.7
  ├─ is-data-view ^1.0.2
  ├─ is-negative-zero ^2.0.3
  ├─ is-regex ^1.2.1 → 1.2.1
  ├─ is-set ^2.0.3
  ├─ is-shared-array-buffer ^1.0.4
  ├─ is-string ^1.1.1
  ├─ is-typed-array ^1.1.15 → 1.1.15
  ├─ is-weakref ^1.1.1
  ├─ math-intrinsics ^1.1.0 → 1.1.0
  ├─ object-inspect ^1.13.4 → 1.13.4
  ├─ object-keys ^1.1.1 → 1.1.1
  ├─ object.assign ^4.1.7 → 4.1.7
  ├─ own-keys ^1.0.1 → 1.0.1
  ├─ regexp.prototype.flags ^1.5.4 → 1.5.4
  ├─ right-align ^0.1.1 → 0.1.3
  ├─ safe-array-concat ^1.1.3
  ├─ safe-push-apply ^1.0.0
  ├─ safe-regex-test ^1.1.0 → 1.1.0
  ├─ set-function-length ^1.2.2 → 1.2.2
  ├─ set-function-name ^2.0.2 → 2.0.2
  ├─ set-proto ^1.0.0
  ├─ stop-iteration-iterator ^1.1.0
  ├─ string.prototype.trimend ^1.0.9 → 1.0.9
  ├─ string.prototype.trimstart ^1.0.8 → 1.0.8
  ├─ typed-array-buffer ^1.0.3 → 1.0.3
  ├─ typed-array-byte-length ^1.0.3 → 1.0.3
  ├─ typed-array-byte-offset ^1.0.4 → 1.0.4
  ├─ typed-array-length ^1.0.7 → 1.0.7
  ├─ unbox-primitive ^1.1.0 → 1.1.0
  ├─ which-typed-array ^1.1.19 → 1.1.21
├─ wordwrap 0.0.2 → 0.0.2
  ├─ align-text ^0.1.1 → 0.1.4
  ├─ align-text ^0.1.3 → 0.1.4
  ├─ array-buffer-byte-length ^1.0.1 → 1.0.2
  ├─ async-function ^1.0.0
  ├─ async-generator-function ^1.0.0 → 1.0.0
  ├─ available-typed-arrays ^1.0.7 → 1.0.7
  ├─ balanced-match ^1.0.0 → 1.0.2
  ├─ call-bind ^1.0.7 → 1.0.9
  ├─ call-bind ^1.0.9 → 1.0.9
  ├─ call-bind ^1.0.8 → 1.0.9
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ call-bound ^1.0.3 → 1.0.4
  ├─ call-bound ^1.0.2 → 1.0.4
  ├─ call-bound ^1.0.4 → 1.0.4
  ├─ concat-map 0.0.1 → 0.0.1
  ├─ define-data-property ^1.1.4
  ├─ define-data-property ^1.0.1
  ├─ define-properties ^1.2.1 → 1.2.1
  ├─ dunder-proto ^1.0.1 → 1.0.1
  ├─ es-define-property ^1.0.0 → 1.0.1
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ es-object-atoms ^1.1.1 → 1.1.2
  ├─ es-object-atoms ^1.0.0 → 1.1.2
  ├─ for-each ^0.3.5 → 0.3.5
  ├─ for-each ^0.3.3 → 0.3.5
  ├─ function-bind ^1.1.2 → 1.1.2
  ├─ functions-have-names ^1.2.3 → 1.2.3
  ├─ functions-have-names ^1.2.3
  ├─ generator-function ^2.0.0 → 2.0.1
  ├─ get-intrinsic ^1.3.0 → 1.3.1
  ├─ get-intrinsic ^1.2.4 → 1.3.1
  ├─ get-intrinsic ^1.2.6 → 1.3.1
  ├─ get-proto ^1.0.1
  ├─ get-proto ^1.0.1 → 1.0.1
  ├─ gopd ^1.2.0 → 1.2.0
  ├─ gopd ^1.0.1 → 1.2.0
  ├─ has-bigints ^1.0.2
  ├─ has-property-descriptors ^1.0.2 → 1.0.2
  ├─ has-property-descriptors ^1.0.0 → 1.0.2
  ├─ has-proto ^1.2.0 → 1.2.0
  ├─ has-symbols ^1.1.0 → 1.1.0
  ├─ has-symbols ^1.0.3 → 1.1.0
  ├─ has-tostringtag ^1.0.2 → 1.0.2
  ├─ hasown ^2.0.2 → 2.0.4
  ├─ is-array-buffer ^3.0.4
  ├─ is-array-buffer ^3.0.5
  ├─ is-callable ^1.2.7 → 1.2.7
  ├─ is-data-view ^1.0.1
  ├─ is-data-view ^1.0.2
  ├─ is-date-object ^1.0.5
  ├─ is-regex ^1.2.1 → 1.2.1
  ├─ is-symbol ^1.0.4
  ├─ is-typed-array ^1.1.15 → 1.1.15
  ├─ is-typed-array ^1.1.14
  ├─ is-typed-array ^1.1.13 → 1.1.15
  ├─ is-typed-array ^1.1.14 → 1.1.15
  ├─ lazy-cache ^1.0.3 → 1.0.4
  ├─ math-intrinsics ^1.1.0 → 1.1.0
  ├─ object-keys ^1.1.1 → 1.1.1
  ├─ possible-typed-array-names ^1.0.0 → 1.1.0
  ├─ reflect.getprototypeof ^1.0.6 → 1.0.10
  ├─ reflect.getprototypeof ^1.0.9 → 1.0.10
  ├─ safe-push-apply ^1.0.0
  ├─ set-function-length ^1.2.2 → 1.2.2
  ├─ set-function-name ^2.0.2 → 2.0.2
  ├─ which-boxed-primitive ^1.1.1 → 1.1.1
├─ which-typed-array ^1.1.16 → 1.1.21
  ├─ async-function ^1.0.0
  ├─ async-generator-function ^1.0.0 → 1.0.0
  ├─ available-typed-arrays ^1.0.7 → 1.0.7
  ├─ call-bind ^1.0.9 → 1.0.9
  ├─ call-bind ^1.0.8 → 1.0.9
  ├─ call-bind-apply-helpers ^1.0.1 → 1.0.2
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ call-bound ^1.0.2 → 1.0.4
  ├─ call-bound ^1.0.4 → 1.0.4
  ├─ call-bound ^1.0.3 → 1.0.4
  ├─ define-data-property ^1.0.1
  ├─ define-data-property ^1.1.4
  ├─ define-properties ^1.2.1 → 1.2.1
  ├─ dunder-proto ^1.0.0 → 1.0.1
  ├─ dunder-proto ^1.0.1 → 1.0.1
  ├─ es-define-property ^1.0.0 → 1.0.1
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ es-object-atoms ^1.1.1 → 1.1.2
  ├─ es-object-atoms ^1.0.0 → 1.1.2
  ├─ for-each ^0.3.5 → 0.3.5
  ├─ function-bind ^1.1.2 → 1.1.2
  ├─ functions-have-names ^1.2.3 → 1.2.3
  ├─ generator-function ^2.0.0 → 2.0.1
  ├─ get-intrinsic ^1.3.0 → 1.3.1
  ├─ get-intrinsic ^1.2.7 → 1.3.1
  ├─ get-intrinsic ^1.2.4 → 1.3.1
  ├─ get-proto ^1.0.1
  ├─ get-proto ^1.0.1 → 1.0.1
  ├─ gopd ^1.0.1 → 1.2.0
  ├─ gopd ^1.2.0 → 1.2.0
  ├─ has-property-descriptors ^1.0.0 → 1.0.2
  ├─ has-property-descriptors ^1.0.2 → 1.0.2
  ├─ has-symbols ^1.1.0 → 1.1.0
  ├─ has-symbols ^1.0.3 → 1.1.0
  ├─ has-tostringtag ^1.0.2 → 1.0.2
  ├─ hasown ^2.0.2 → 2.0.4
  ├─ is-array-buffer ^3.0.5
  ├─ is-bigint ^1.1.0
  ├─ is-boolean-object ^1.2.1
  ├─ is-callable ^1.2.7 → 1.2.7
  ├─ is-number-object ^1.1.1
  ├─ is-string ^1.1.1 → 1.1.1
  ├─ is-symbol ^1.1.1 → 1.1.1
  ├─ kind-of ^3.0.2 → 3.2.2
  ├─ longest ^1.0.1 → 1.0.1
  ├─ math-intrinsics ^1.1.0 → 1.1.0
  ├─ object-keys ^1.1.1 → 1.1.1
  ├─ possible-typed-array-names ^1.0.0 → 1.1.0
  ├─ repeat-string ^1.5.2 → 1.6.1
  ├─ set-function-length ^1.2.2 → 1.2.2
  ├─ which-builtin-type ^1.2.1 → 1.2.1
├─ which-typed-array ^1.1.16 → 1.1.21
  ├─ async-function ^1.0.0
  ├─ async-generator-function ^1.0.0 → 1.0.0
  ├─ available-typed-arrays ^1.0.7 → 1.0.7
  ├─ call-bind ^1.0.9 → 1.0.9
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ call-bind-apply-helpers ^1.0.1 → 1.0.2
  ├─ call-bound ^1.0.3 → 1.0.4
  ├─ call-bound ^1.0.2 → 1.0.4
  ├─ call-bound ^1.0.4 → 1.0.4
  ├─ define-data-property ^1.0.1
  ├─ define-data-property ^1.1.4
  ├─ dunder-proto ^1.0.1 → 1.0.1
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-define-property ^1.0.0 → 1.0.1
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ es-object-atoms ^1.1.1 → 1.1.2
  ├─ es-object-atoms ^1.0.0 → 1.1.2
  ├─ for-each ^0.3.5 → 0.3.5
  ├─ function-bind ^1.1.2 → 1.1.2
  ├─ function.prototype.name ^1.1.6 → 1.1.8
  ├─ generator-function ^2.0.0 → 2.0.1
  ├─ get-intrinsic ^1.3.0 → 1.3.1
  ├─ get-intrinsic ^1.2.4 → 1.3.1
  ├─ get-proto ^1.0.1 → 1.0.1
  ├─ get-proto ^1.0.1
  ├─ gopd ^1.2.0 → 1.2.0
  ├─ gopd ^1.0.1 → 1.2.0
  ├─ has-property-descriptors ^1.0.0 → 1.0.2
  ├─ has-property-descriptors ^1.0.2 → 1.0.2
  ├─ has-symbols ^1.1.0 → 1.1.0
  ├─ has-symbols ^1.0.3 → 1.1.0
  ├─ has-tostringtag ^1.0.2 → 1.0.2
  ├─ hasown ^2.0.2 → 2.0.4
  ├─ is-async-function ^2.0.0 → 2.1.1
  ├─ is-buffer ^1.1.5 → 1.1.6
  ├─ is-callable ^1.2.7 → 1.2.7
  ├─ is-date-object ^1.1.0 → 1.1.0
  ├─ is-finalizationregistry ^1.1.0
  ├─ is-generator-function ^1.0.10 → 1.1.2
  ├─ is-regex ^1.2.1 → 1.2.1
  ├─ is-weakref ^1.0.2 → 1.1.1
  ├─ isarray ^2.0.5 → 2.0.5
  ├─ math-intrinsics ^1.1.0 → 1.1.0
  ├─ object-keys ^1.1.1 → 1.1.1
  ├─ possible-typed-array-names ^1.0.0 → 1.1.0
  ├─ safe-regex-test ^1.1.0 → 1.1.0
  ├─ set-function-length ^1.2.2 → 1.2.2
  ├─ which-boxed-primitive ^1.1.0 → 1.1.1
  ├─ which-collection ^1.0.2 → 1.0.2
├─ which-typed-array ^1.1.16 → 1.1.21
  ├─ async-function ^1.0.0
  ├─ async-generator-function ^1.0.0 → 1.0.0
  ├─ available-typed-arrays ^1.0.7 → 1.0.7
  ├─ call-bind ^1.0.8 → 1.0.9
  ├─ call-bind ^1.0.9 → 1.0.9
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ call-bind-apply-helpers ^1.0.1 → 1.0.2
  ├─ call-bound ^1.0.3 → 1.0.4
  ├─ call-bound ^1.0.2 → 1.0.4
  ├─ call-bound ^1.0.4 → 1.0.4
  ├─ define-data-property ^1.1.4
  ├─ define-properties ^1.2.1 → 1.2.1
  ├─ dunder-proto ^1.0.1 → 1.0.1
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-define-property ^1.0.0 → 1.0.1
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ es-object-atoms ^1.1.1 → 1.1.2
  ├─ es-object-atoms ^1.0.0 → 1.1.2
  ├─ for-each ^0.3.5 → 0.3.5
  ├─ function-bind ^1.1.2 → 1.1.2
  ├─ functions-have-names ^1.2.3
  ├─ generator-function ^2.0.0 → 2.0.1
  ├─ get-intrinsic ^1.2.4 → 1.3.1
  ├─ get-intrinsic ^1.3.0 → 1.3.1
  ├─ get-proto ^1.0.1
  ├─ get-proto ^1.0.1 → 1.0.1
  ├─ gopd ^1.0.1 → 1.2.0
  ├─ gopd ^1.2.0 → 1.2.0
  ├─ has-property-descriptors ^1.0.2 → 1.0.2
  ├─ has-symbols ^1.1.0 → 1.1.0
  ├─ has-symbols ^1.0.3 → 1.1.0
  ├─ has-tostringtag ^1.0.2 → 1.0.2
  ├─ hasown ^2.0.2 → 2.0.4
  ├─ is-bigint ^1.1.0
  ├─ is-boolean-object ^1.2.1
  ├─ is-callable ^1.2.7 → 1.2.7
  ├─ is-map ^2.0.3
  ├─ is-number-object ^1.1.1
  ├─ is-regex ^1.2.1 → 1.2.1
  ├─ is-set ^2.0.3 → 2.0.3
  ├─ is-string ^1.1.1 → 1.1.1
  ├─ is-symbol ^1.1.1 → 1.1.1
  ├─ is-weakmap ^2.0.2
  ├─ is-weakset ^2.0.3
  ├─ math-intrinsics ^1.1.0 → 1.1.0
  ├─ possible-typed-array-names ^1.0.0 → 1.1.0
  ├─ safe-regex-test ^1.1.0 → 1.1.0
├─ set-function-length ^1.2.2 → 1.2.2
  ├─ async-function ^1.0.0
  ├─ async-generator-function ^1.0.0 → 1.0.0
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ call-bind-apply-helpers ^1.0.1 → 1.0.2
  ├─ call-bound ^1.0.2 → 1.0.4
  ├─ call-bound ^1.0.3 → 1.0.4
  ├─ define-data-property ^1.1.4
  ├─ define-data-property ^1.0.1
  ├─ dunder-proto ^1.0.1 → 1.0.1
  ├─ es-define-property ^1.0.0 → 1.0.1
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ es-object-atoms ^1.0.0 → 1.1.2
  ├─ es-object-atoms ^1.1.1 → 1.1.2
  ├─ function-bind ^1.1.2 → 1.1.2
  ├─ generator-function ^2.0.0 → 2.0.1
  ├─ get-intrinsic ^1.2.4 → 1.3.1
  ├─ get-intrinsic ^1.3.0 → 1.3.1
  ├─ get-proto ^1.0.1
  ├─ gopd ^1.2.0 → 1.2.0
  ├─ gopd ^1.0.1 → 1.2.0
  ├─ has-property-descriptors ^1.0.0 → 1.0.2
  ├─ has-property-descriptors ^1.0.2 → 1.0.2
  ├─ has-symbols ^1.0.3 → 1.1.0
  ├─ has-symbols ^1.1.0 → 1.1.0
  ├─ has-tostringtag ^1.0.2 → 1.0.2
  ├─ hasown ^2.0.2 → 2.0.4
  ├─ is-callable ^1.2.7 → 1.2.7
  ├─ is-regex ^1.2.1 → 1.2.1
  ├─ math-intrinsics ^1.1.0 → 1.1.0
  ├─ object-keys ^1.1.1 → 1.1.1
  ├─ possible-typed-array-names ^1.0.0 → 1.1.0
  ├─ safe-regex-test ^1.1.0 → 1.1.0
  ├─ set-function-length ^1.2.2 → 1.2.2

Changes from v2.4.35

Dependency Changes

Script Changes

+ preinstall

File Changes

1 added 0 removed 1 modified size delta: +486.9 KB

Risk Dispositions (5 applicable to this version, 0 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Rule Source Disposition Author Reason
install-script:preinstall install-scripts reject AI AI (install-scripts): Preinstall running obfuscated index.js is malicious; not a legitimate pattern for this charting library.
obfuscated-file:index.js source-diff reject AI AI (source-diff): Obfuscated payload added in this version; not present in prior legitimate releases.
url-dep:@antv/setup npm-metadata reject AI AI (npm-metadata): SHA-pinned GitHub optionalDependency matches known supply-chain attack pattern; not a legitimate dependency for this package.
semgrep:obfuscation-while-true semgrep reject AI AI (semgrep): javascript-obfuscator signature in newly added index.js; confirms malicious payload.
semgrep:env-spread semgrep reject AI AI (semgrep): process.env spread in obfuscated payload indicates credential exfiltration intent.

SAST Findings (11)

HIGH Package has 'preinstall' script install-scripts

Script: bun run index.js

HIGH SHA-pinned github dependency (optionalDependencies): @antv/setup npm-metadata

Dependency '@antv/setup' in `optionalDependencies` points to 'github:antvis/G2#1916faa365f2788b6e193514872d51a242876569' instead of a registry version. URL dependencies bypass the registry and can be swapped at any time. A 40-character commit SHA in a dependency URL is a strong supply-chain signal — the 2026-05-11 TanStack/Mini Shai-Hulud attack used this exact shape in `optionalDependencies` to smuggle a malicious payload past lifecycle-script and OSV checks.

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atool.

HIGH Publisher changed: siqishen → atool (on 2026-05-19) provenance

This version was published by a different npm account than previous versions on 2026-05-19. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH obfuscation-while-true: index.js:1 semgrep

while(!![]) loop is a signature of javascript-obfuscator output > 1 | const _0x5d6bea=_0x1169;(function(_0x3187cf,_0x895a8e){const _0x5f2282={_0x2bb395:0x3eb,_0x56f5b5:0x6c1,_0x24d254:0x85d,

HIGH obfuscation-hex-functions: index.js:1 semgrep

Hex-prefixed function names (_0x...) are generated by javascript-obfuscator > 1 | const _0x5d6bea=_0x1169;(function(_0x3187cf,_0x895a8e){const _0x5f2282={_0x2bb395:0x3eb,_0x56f5b5:0x6c1,_0x24d254:0x85d,

HIGH obfuscation-hex-functions: index.js:1 semgrep

Hex-prefixed function names (_0x...) are generated by javascript-obfuscator > 1 | const _0x5d6bea=_0x1169;(function(_0x3187cf,_0x895a8e){const _0x5f2282={_0x2bb395:0x3eb,_0x56f5b5:0x6c1,_0x24d254:0x85d,

HIGH env-spread: index.js:1 semgrep

Spreading entire process.env into an object — may capture all secrets > 1 | const _0x5d6bea=_0x1169;(function(_0x3187cf,_0x895a8e){const _0x5f2282={_0x2bb395:0x3eb,_0x56f5b5:0x6c1,_0x24d254:0x85d,

HIGH obfuscation-hex-functions: index.js:1 semgrep

Hex-prefixed function names (_0x...) are generated by javascript-obfuscator > 1 | const _0x5d6bea=_0x1169;(function(_0x3187cf,_0x895a8e){const _0x5f2282={_0x2bb395:0x3eb,_0x56f5b5:0x6c1,_0x24d254:0x85d,

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

Review Summary

Risk score: 100 (capped from 270). Findings: 10 high (+250), 2 medium (+20), 2 info (+0).

Published to npm: