PkgRadar

npm · registry.npmjs.org

@checkstack/script-packages-backend

Credential file access: matched ".npmrc"

Why PkgRadar flagged 0.3.13

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/src/audit-scanner.ts
mediumCredential file accessmatched ".npmrc" · package/src/resolver.test.ts
mediumCredential file accessmatched ".npmrc" · package/src/resolver.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.13Review302026-06-14
0.3.12Review302026-06-11
0.3.11Review302026-06-09
0.3.10Review302026-06-08
0.3.9Review302026-06-08
0.3.8Review302026-06-08
0.3.7Review302026-06-07
0.3.6Review302026-06-07
0.3.5Review302026-06-07
0.3.4Review302026-06-06
0.3.3Review302026-06-06
0.3.2Review302026-06-05
0.3.1Review302026-06-05
0.3.0Review302026-06-05
0.2.0Review202026-06-01
0.2.1Review202026-06-01

Block this in CI

PkgRadar gates @checkstack/script-packages-backend (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @checkstack/[email protected]