PkgRadar

npm · registry.npmjs.org

@equinor/echo-cli

Credential File Packaged: package/lib/echo-dev-host/.env

Why PkgRadar flagged 6.0.0-edsv2-beta-2

SeveritySignalEvidence
highCredential File Packagedpackage/lib/echo-dev-host/.env · package/lib/echo-dev-host/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
6.0.0-edsv2-beta-2Review102026-06-08
5.0.0Review102026-06-08
5.0.0-beta-r19-0Review102026-06-08
5.0.0-beta-r19-1Review102026-06-08
6.0.0-edsv2-beta-1Review102026-06-08

Block this in CI

PkgRadar gates @equinor/echo-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @equinor/[email protected]