PkgRadar

npm · registry.npmjs.org

@checksum-ai/runtime

Credential File Packaged: package/.env

Why PkgRadar flagged 4.1.1-beta.12

SeveritySignalEvidence
highCredential File Packagedpackage/.env · package/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
4.1.1-beta.12High risk172026-06-13
4.1.1-beta.11High risk172026-06-13
4.1.1-beta.9High risk172026-06-13
4.1.1-beta.8High risk172026-06-13
4.1.1-beta.7High risk172026-06-13
4.1.1-beta.6High risk172026-06-10
4.1.1-beta.5High risk172026-06-10
4.3.2-beta.2High risk172026-06-10
4.3.2-beta.1High risk172026-06-10
4.3.2High risk172026-06-10
4.3.1High risk172026-06-10
4.3.0-beta.2High risk172026-06-10
4.3.0-beta.1High risk172026-06-10
4.3.0High risk172026-06-10
4.2.0-beta.14High risk172026-06-10
4.2.0High risk172026-06-10
4.1.1-beta.13High risk172026-06-10
4.1.1-beta.4Review652026-05-25
4.1.1-beta.3Review652026-05-25
4.1.1Review752026-05-25
4.1.1-beta.2Review652026-05-25

Block this in CI

PkgRadar gates @checksum-ai/runtime (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @checksum-ai/[email protected]