PkgRadar

npm · registry.npmjs.org

@etsoo/smarterp-core

Credential file access: matched ".npmrc"

Why PkgRadar flagged 1.1.48

SeveritySignalEvidence
highCredential file accessmatched ".npmrc" · package/.github/workflows/main.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.59Low risk02026-06-12
1.1.58Low risk02026-06-12
1.1.57Low risk02026-06-09
1.1.56Low risk02026-06-06
1.1.55Low risk02026-05-31
1.1.54Low risk02026-05-31
1.1.53Low risk02026-05-26
1.1.52Low risk02026-05-26
1.1.51Low risk02026-05-25
1.1.50Low risk02026-05-25
1.1.49Low risk02026-05-25
1.1.48Review302026-05-25
1.1.47Review302026-05-24
1.1.46Review302026-05-24
1.1.44Review302026-05-24
1.1.45Review302026-05-24

Block this in CI

PkgRadar gates @etsoo/smarterp-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @etsoo/[email protected]