PkgRadar

npm · registry.npmjs.org

@florianpat/lando-core

Known Indicator Filename: package/node_modules/@sigstore/bundle/dist/bundle.js

Why PkgRadar flagged 3.26.3-1florianPat.15

SeveritySignalEvidence
highKnown Indicator Filenamepackage/node_modules/@sigstore/bundle/dist/bundle.js · package/node_modules/@sigstore/bundle/dist/bundle.js
highKnown Indicator Filenamepackage/node_modules/@sigstore/sign/dist/bundler/bundle.js · package/node_modules/@sigstore/sign/dist/bundler/bundle.js
highCredential file accessmatched ".ssh" · package/builders/_lando.js
highCredential file accessmatched ".ssh" · package/hooks/app-check-ssh-keys.js
highCredential file accessmatched ".ssh" · package/node_modules/@npmcli/arborist/lib/consistent-resolve.js
highCredential file accessmatched ".ssh" · package/node_modules/@npmcli/arborist/lib/dep-valid.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/node_modules/@npmcli/agent/lib/dns.js
highDNS / OAST exfiltrationmatched "dns.resolve" · package/node_modules/retry/example/dns.js
highCredential file accessmatched ".ssh" · package/node_modules/node-forge/dist/forge.all.min.js
highCredential file accessmatched ".ssh" · package/node_modules/node-forge/dist/forge.min.js
highCredential file accessmatched ".ssh" · package/node_modules/pacote/lib/git.js
highCredential file accessmatched "id_rsa" · package/sources/github.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.26.3-1florianPat.15Review3402026-05-24
3.26.5-1florianPat.0Review3402026-05-24

Related campaigns

Block this in CI

PkgRadar gates @florianpat/lando-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @florianpat/[email protected]