Analyze your own packages withvet GitHub

@img/sharp-libvips-linux-arm64@1.2.3

Safe
Analyzed at:9/17/2025, 10:35:21 AM
Source:https://registry.npmjs.org/@img/sharp-libvips-linux-arm64/-/sharp-libvips-linux-arm64-1.2.3.tgz
SHA256:8af2aceb7a9abd171bb03241e4cafe040cb9e490616b4b4de984f015ca9bcfdb
Confidence:Medium
Summary

This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.

The package contains a shared object file, which is an executable and a common practice for libraries requiring native code. Not classified as malware.

Details

The package contains a shared object file (libvips-cpp.so.8.17.2) which is an executable. This is a common practice for libraries that require native code. The extension mismatch is minor and likely due to versioning. Without further evidence of malicious behavior, the package is not classified as malware.