SafeDep
Install GitHub App

Summary

Insufficient evidence to classify as malware. Missing project info is not conclusive proof of malicious intent.

Verification Record

No verification record available.

Details

Based solely on the provided evidence, we cannot definitively classify minipass-pipeline version 1.2.4 as malware. Evidence 0 indicates a lack of source project information. This is insufficient to label the package as malicious. The absence of project information could be due to several benign reasons: the project is very new, the repository is private, or our database simply hasn't indexed it yet. Without further evidence such as suspicious code analysis (LLM or otherwise), unusual network behavior, or confirmed malicious functionality, we cannot conclude that it is malware. The low confidence level assigned to Evidence 0 further supports this conclusion. More information is needed before a determination can be made.

minipass-pipeline@1.2.4Clean
Unverified
Analysed at: 3/10/25, 1:17 PM
Source: https://registry.npmjs.org/minipass-pipeline/-/minipass-pipeline-1.2.4.tgz
SHA256: 0b64f23832fd6391b879182615c6d0363371b0df2fa37a7d63e30903b156078f
Confidence: Medium