npm package report

Is sinon safe?

Checked against the XYZ decision brain: known-malicious corpus, advisories, commit-level findings, dependencies and provenance.

cyberxyz.io/packages/npm/sinon
npm packagelast checked 2026-09-19

sinon · verdict ALLOW · no known risk

0.6/10
XYZ SCORE
SUMMARY

Verdict ALLOW · 14 graph-tracked dependencies · 1 flagged · provenance: none found

Re-check live →

SIGNALS
Commit-Level AnalysisclearOK

3 unconfirmed pattern hit(s) in watched commit history; none verified as malicious.

Anomaly HistoryclearOK

1 historical anomaly alert(s) (transitive_malicious_dep) on this package. Add a version to check whether it is affected.

DEPENDENCIES
@babel/core@^7.14.3clean
babelify@^10.0.0clean
babel-plugin-istanbul@^5.1.0clean
browserify@^11.1.0clean
build@^0.1.4clean
buster@0.7.18clean
buster-assertions@~0.10clean
buster-core@~0.6clean
buster-evented-logger@~0.4clean
buster-format@~0.5clean
buster-istanbul@0.1.13clean
buster-test@~0.5clean
colors@^1.1.2block
debug@^4.3.1clean
PACKAGE sinonECOSYSTEM npmDECISION ALLOW

Package facts

Weekly downloads
49.6M
Centrality tier
tier 1
Build provenance
none found
Direct dependencies
14
Flagged dependencies
1

Baked snapshot · run a live check for the current verdict · browse all packages

Other package reports

socket.iostyled-componentssuperagentsharpsequelizesemver

See all package reports or check any package live.