PkgRadar

npm · registry.npmjs.org

@alanjaouen2/sfp

Credential file access: matched ".npmrc"

Why PkgRadar flagged 39.0.3

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/lib/impl/artifacts/FetchAnArtifactFromNPM.js
mediumCredential file accessmatched ".npmrc" · package/lib/commands/publish.js

Scanned versions

VersionVerdictScoreScanned (UTC)
39.0.3Review402026-06-08
39.0.2Review402026-06-08

Block this in CI

PkgRadar gates @alanjaouen2/sfp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @alanjaouen2/[email protected]