PkgRadar

npm · registry.npmjs.org

@chiranjib-infosys/repro-oidc-setup-node

Ci Workflow Secret Harvesting: workflow references CI/cloud credential harvesting surfaces

Why PkgRadar flagged 0.0.50

SeveritySignalEvidence
highCi Workflow Secret Harvestingworkflow references CI/cloud credential harvesting surfaces · package/.github/workflows/publish2.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.50Review192026-05-26
0.0.49Review692026-05-25
0.0.47Review1502026-05-25
0.0.48Review1452026-05-25

Block this in CI

PkgRadar gates @chiranjib-infosys/repro-oidc-setup-node (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @chiranjib-infosys/[email protected]
@chiranjib-infosys/repro-oidc-setup-node — npm security scan | PkgRadar