PkgRadar

npm · registry.npmjs.org

@decaf-ts/utils

Credential file access: matched "NPM_TOKEN"

Why PkgRadar flagged 1.6.0

SeveritySignalEvidence
highCredential file accessmatched "NPM_TOKEN" · package/lib/esm/cli/commands/tag-release-shell.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/lib/cjs/release-chain/index.cjs
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/utils.cjs
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/lib/esm/release-chain/index.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/utils.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.0Review392026-06-04
1.5.6Review562026-05-27
1.5.5Review562026-05-27
1.5.4Review562026-05-25
1.5.3Review562026-05-25
1.5.1Review1482026-05-24
1.5.2Review1482026-05-24

Block this in CI

PkgRadar gates @decaf-ts/utils (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @decaf-ts/[email protected]