PkgRadar

npm · registry.npmjs.org

@coder/codex-server

Credential file access: matched ".ssh"

Why PkgRadar flagged 26.513.20950

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/am-BZW2E1OZ.js
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/app-main-Dsg36Y4q.js
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/ar-BBFSzsrA.js
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/bg-BG-Bx27VwLC.js
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/bn-BD-Bemqc_e9.js
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/bs-BA-B_764pQ1.js
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/ca-ES-fSSV7oSw.js
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/cs-CZ-Ww7blGnf.js
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/da-DK-e3KtrDrB.js
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/de-DE-BolUFQhy.js
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/debug-modal-CKcdboWI.js
highCredential file accessmatched ".ssh" · package/scratch/asar/webview/assets/el-GR-Db4ne67s.js

Scanned versions

VersionVerdictScoreScanned (UTC)
26.513.20950Review1562026-05-24

Block this in CI

PkgRadar gates @coder/codex-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @coder/[email protected]