PkgRadar

npm · registry.npmjs.org

@cuongtran001/kanna

Credential file access: matched "id_rsa"

Why PkgRadar flagged 0.92.2

SeveritySignalEvidence
mediumCredential file accessmatched "id_rsa" · package/src/server/claude-pty/sandbox/preflight.test.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.92.2Review452026-06-12
0.92.0Review312026-06-10
0.91.0Review452026-06-08
0.90.1Review312026-06-08
0.90.0Review312026-06-07
0.88.1Review312026-06-07
0.89.0Review312026-06-07
0.88.0Review312026-06-06
0.87.0Review312026-06-06
0.86.0Review312026-06-05
0.85.2Review312026-06-04
0.85.1Review312026-06-04
0.85.0Review312026-06-04
0.84.1Review312026-06-04
0.84.0Review312026-06-04
0.83.0Review312026-06-03
0.83.1Review312026-06-03
0.82.0Review312026-06-03
0.81.3Review312026-06-03
0.81.2Review312026-06-02
0.81.1Review312026-06-02
0.81.0Review312026-06-01
0.80.0Review312026-05-31
0.79.0Review312026-05-30
0.78.0Review312026-05-29
0.77.2Review582026-05-25
0.77.1Review842026-05-25
0.77.0Review1082026-05-25
0.76.0Review1372026-05-25
0.74.0Review1142026-05-24
0.75.0Review1142026-05-24

Block this in CI

PkgRadar gates @cuongtran001/kanna (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @cuongtran001/[email protected]