PkgRadar

npm · registry.npmjs.org

@codiac.io/codiac-cli

Credential file access: matched ".npmrc"

Why PkgRadar flagged 1.3.234

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/dist/ops/i-identity-handler.js
mediumCredential file accessmatched ".npmrc" · package/dist/ops/LocalOps.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.234Review72026-06-16
1.3.233Review72026-06-12
1.3.232Review72026-06-09
1.3.230Review72026-06-09
1.3.229Review72026-06-05
1.3.227Review72026-06-04
1.3.228Review72026-06-04
1.3.226Review72026-06-04
1.3.224Review72026-05-29
1.3.225Review72026-05-29
1.3.220Review72026-05-29
1.3.221Review72026-05-29
1.3.219Review172026-05-28
1.3.217Review272026-05-28
1.3.218Review272026-05-28

Block this in CI

PkgRadar gates @codiac.io/codiac-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @codiac.io/[email protected]