PkgRadar

npm · registry.npmjs.org

@blockrun/franklin

Credential file access: matched ".config/gcloud"

Why PkgRadar flagged 3.28.3

SeveritySignalEvidence
mediumCredential file accessmatched ".config/gcloud" · package/dist/tools/write.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.28.3Review102026-06-13
3.28.2Review102026-06-13
3.28.1Review102026-06-10
3.28.0Review152026-06-10
3.27.3Review102026-06-08
3.27.2Review152026-06-08
3.27.1Review102026-06-08
3.26.1Review102026-06-07
3.27.0Review102026-06-07
3.26.0Review102026-06-06
3.25.4Review102026-06-04
3.25.3Review102026-06-03
3.25.2Review102026-06-03
3.25.1Review102026-06-03
3.25.0Review152026-06-02
3.24.4Review102026-06-02
3.24.2Review102026-06-01
3.24.1Review102026-06-01
3.24.0Review102026-05-31
3.23.1Review102026-05-31
3.23.0Review102026-05-29
3.21.9Review142026-05-26
3.22.0Review142026-05-26

Block this in CI

PkgRadar gates @blockrun/franklin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @blockrun/[email protected]