Analyze your own packages withvet GitHub

@img/sharp-libvips-darwin-arm64@1.2.3

Safe
Analyzed at:9/17/2025, 10:35:14 AM
Source:https://registry.npmjs.org/@img/sharp-libvips-darwin-arm64/-/sharp-libvips-darwin-arm64-1.2.3.tgz
SHA256:2ef3c1ad27be41b86c7d516e278ada427f913686fd1510629c6ac54e9506d31b
Confidence:Medium
Summary

This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.

Package contains a .dylib (dynamic library) file, which is standard for macOS. File extension mismatch is expected. Not classified as malware.

Details

The package contains a .dylib file, which is a dynamic library for macOS. The file extension mismatch is flagged, but the file is identified as a Mach-O binary, which is expected for .dylib files on macOS. While the embedded executable raises a medium confidence alert, it is a valid use case for pre-compiled binaries in packages. Therefore, based on the available evidence, the package is not classified as malware.