PkgRadar

npm · registry.npmjs.org

@deppon/create-deppon-app

Credential File Packaged: package/template/.env

Why PkgRadar flagged 2.5.8

SeveritySignalEvidence
highCredential File Packagedpackage/template/.env · package/template/.env
mediumCredential file accessmatched ".npmrc" · package/deppon.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.5.8High risk502026-06-10
2.5.9High risk502026-06-10
2.5.12High risk502026-06-10
2.5.11High risk502026-06-10
2.5.10High risk502026-06-10
2.5.7High risk502026-06-10
2.5.6High risk502026-06-10

Related campaigns

Block this in CI

PkgRadar gates @deppon/create-deppon-app (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @deppon/[email protected]