Analyze your own packages withvet GitHub

@img/sharp-libvips-linuxmusl-arm64@1.2.3

Safe
Analyzed at:9/23/2025, 5:58:26 PM
Source:https://registry.npmjs.org/@img/sharp-libvips-linuxmusl-arm64/-/sharp-libvips-linuxmusl-arm64-1.2.3.tgz
SHA256:940a883c6c90c6a15598cd27338cb904ddb0b9c18d507b7ffb9cbec17bfab63d
Confidence:Medium
Summary

This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.

The package contains a shared object, which is normal for native bindings. Verified provenance and no strong indicators of malicious intent.

Details

The package @img/sharp-libvips-linuxmusl-arm64 contains a shared object file (libvips-cpp.so.8.17.2) which is an ELF executable. This is expected behavior for a library that provides native bindings. The extension mismatch is minor and doesn't indicate malicious intent. The SLSA provenance is also verified, adding confidence to the package's integrity. Therefore, the package is not considered malware.