PkgRadar

npm · registry.npmjs.org

@companyhelm/cli

Credential file access: matched ".aws/"

Why PkgRadar flagged 0.4.1

SeveritySignalEvidence
highCredential file accessmatched ".aws/" · package/dist/core/runtime/PublicImageTagRegistry.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.8Low risk02026-06-15
0.4.5Low risk02026-06-05
0.4.6Low risk02026-06-05
0.4.3Low risk02026-06-05
0.4.1Review132026-06-03
0.4.2Low risk02026-06-03

Block this in CI

PkgRadar gates @companyhelm/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @companyhelm/[email protected]