PkgRadar

Go modules · proxy.golang.org

github.com/sapphir3-ros3/solomon

Credential file access: matched ".npmrc"

Why PkgRadar flagged v0.0.0-20260528090354-cb9456dccbce

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · github.com/sapphir3-ros3/[email protected]/internal/integrations/cursor/bootstrap.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260528090354-cb9456dccbceReview102026-05-30
v0.20260522.0Low risk02026-05-29
v0.20260522.1Low risk02026-05-29
v0.20260522.2Low risk02026-05-29
v0.20260525.0Low risk02026-05-29
v0.20260525.1Review102026-05-29
v0.20260525.3Review102026-05-29
v0.20260525.4Review102026-05-29
v0.20260526.0Review102026-05-29
v0.20260526.1Review102026-05-29
v0.20260526.2Review102026-05-29
v0.20260526.3Review102026-05-29
v0.20260527.1Review102026-05-29
v0.20260527.0Review102026-05-29
v0.20260523.0Low risk02026-05-29

Block this in CI

PkgRadar gates github.com/sapphir3-ros3/solomon (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/sapphir3-ros3/[email protected]