PkgRadar

npm · registry.npmjs.org

@blockrun/runcode

Credential file access

Why PkgRadar flagged 2.5.41

SeveritySignalEvidence
mediumCredential file accesspackage/dist/tools/write.js

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
2.5.41Review102026-06-25
2.6.0Review102026-06-25
2.7.0Review102026-06-25
2.8.0Review102026-06-25

Block this in CI

PkgRadar gates @blockrun/runcode (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @blockrun/[email protected]