PkgRadar

npm · registry.npmjs.org

@devtrack-solution/codesdd

Credential file access: matched ".npmrc"

Why PkgRadar flagged 1.2.4-rc3

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/dist/core/sdd/release-readiness.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.4-rc3Review302026-06-01
1.2.2Review52026-05-30
1.2.3Review152026-05-30

Block this in CI

PkgRadar gates @devtrack-solution/codesdd (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @devtrack-solution/[email protected]