PkgRadar

npm · registry.npmjs.org

@aws-amplify/cli

Credential file access

Why PkgRadar flagged 1.5.3

SeveritySignalEvidence
mediumCredential file accesspackage/src/lib/global-prefix.js

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.3Review32026-06-25
14.4.0Review12026-06-25
7.3.0-graphql-vnext-dev-preview.12Review122026-06-25
7.6.24-pin-codegen-dependency.0Review122026-06-25
14.5.0-rc.b96c3c8fd02d4ef.0Review12026-06-25
14.5.0Review12026-06-25
14.5.1-rc.f83740d522c1935.0Review12026-06-25

Block this in CI

PkgRadar gates @aws-amplify/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @aws-amplify/[email protected]