PkgRadar

npm · registry.npmjs.org

@firecms/cli

Credential File Packaged: package/templates/template_pro/.env

Why PkgRadar flagged 3.3.0-canary.3afa809

SeveritySignalEvidence
highCredential File Packagedpackage/templates/template_pro/.env · package/templates/template_pro/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
3.3.0-canary.3afa809High risk172026-06-10
3.3.0-canary.9452021High risk172026-06-10
3.3.0-canary.102f274High risk172026-06-10
3.3.0-canary.3ea2cd2High risk172026-06-10
3.3.0-canary.ae3fdc5High risk172026-06-10
3.3.0-canary.9f007c7High risk172026-06-10
3.3.0-canary.040c21cHigh risk172026-06-10
3.3.0-canary.d3242ebHigh risk172026-06-10
3.3.0-canary.a5780ceHigh risk172026-06-10
3.3.0-canary.2064433High risk172026-06-10
3.3.0-canary.451aa49High risk172026-06-10
3.3.0-canary.7e3431bHigh risk172026-06-10

Block this in CI

PkgRadar gates @firecms/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @firecms/[email protected]