PkgRadar

npm · registry.npmjs.org

@andyqiu/codeforge

Credential file access: matched "id_rsa"

Why PkgRadar flagged 0.8.34

SeveritySignalEvidence
highCredential file accessmatched "id_rsa" · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.34High risk242026-06-17
0.8.33High risk242026-06-17
0.8.32High risk242026-06-17
0.8.31High risk242026-06-17
0.8.30High risk242026-06-17
0.8.29High risk242026-06-17
0.8.27High risk242026-06-17
0.8.28High risk242026-06-17
0.8.26High risk242026-06-17
0.8.25High risk242026-06-17
0.8.23High risk242026-06-16
0.8.24High risk242026-06-16
0.8.22High risk242026-06-16
0.8.21High risk242026-06-16
0.8.20High risk242026-06-16
0.8.19High risk242026-06-16
0.8.18High risk242026-06-16
0.8.17High risk242026-06-16
0.8.16High risk242026-06-16
0.8.15High risk242026-06-16
0.8.14High risk242026-06-16
0.8.13High risk242026-06-16
0.8.12High risk242026-06-15
0.8.11High risk242026-06-15
0.8.10Review32026-06-15
0.8.9Review32026-06-15
0.8.8Review32026-06-15
0.8.7Review32026-06-15
0.8.6Review32026-06-15
0.8.5Review32026-06-12
0.8.4Review32026-06-12
0.8.3Review32026-06-12
0.8.2Review32026-06-12
0.8.1Review32026-06-12
0.8.0Review32026-06-12
0.7.10Review32026-06-12
0.7.9Review32026-06-12
0.7.8Review32026-06-12
0.7.7Review32026-06-12
0.7.4Review32026-06-12
0.7.3Review32026-06-12
0.7.2Review32026-06-12
0.7.1Review32026-06-12
0.7.0Review32026-06-11
0.6.13Review32026-06-11
0.6.12Review32026-06-11
0.6.8Review32026-06-10
0.6.7Review32026-06-10
0.6.6Review32026-06-10
0.3.14High risk452026-06-10
0.6.5Review32026-06-09
0.6.4Review32026-06-05
0.6.2Review52026-06-04
0.6.3Review32026-06-04
0.5.29Review32026-06-03
0.5.27Review52026-06-02
0.5.28Review32026-06-02
0.5.26Review32026-06-01
0.5.25Review102026-05-29
0.5.24Review102026-05-29
0.5.22Review72026-05-29
0.5.21Review72026-05-29
0.5.20Review72026-05-29
0.5.19Review72026-05-29
0.5.18Review102026-05-29
0.5.16Review72026-05-28
0.5.15Review72026-05-28
0.5.11Review72026-05-28
0.5.9Review72026-05-27
0.5.10Review72026-05-27
0.5.7Review72026-05-27
0.5.8Review72026-05-27
0.5.5Review72026-05-26
0.5.6Review72026-05-26
0.5.2Review102026-05-26
0.5.3Review72026-05-26
0.5.1Review102026-05-26
0.4.0Review222026-05-25
0.5.0Review222026-05-25
0.3.13Review722026-05-25

Block this in CI

PkgRadar gates @andyqiu/codeforge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @andyqiu/[email protected]