PkgRadar

npm · registry.npmjs.org

@bitblit/ratchet-aws

Credential file access: matched ".ssh/"

Why PkgRadar flagged 6.1.199-alpha

SeveritySignalEvidence
mediumCredential file accessmatched ".ssh/" · package/src/ec2/ec2-ratchet.spec.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
4.0.119-alphaLow risk02026-06-19
4.0.120-alphaLow risk02026-06-19
4.0.121-alphaLow risk02026-06-19
5.1.122-alphaLow risk02026-06-19
6.1.199-alphaReview32026-06-19
6.1.200-alphaReview32026-06-19
6.1.201-alphaReview32026-06-19
6.1.208-alphaReview32026-06-19

Block this in CI

PkgRadar gates @bitblit/ratchet-aws (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bitblit/[email protected]