PkgRadar

npm · registry.npmjs.org

@flowfuse/nr-launcher

Credential file access: matched ".npmrc"

Why PkgRadar flagged 2.31.3-1aa3ebe-202606091427.0

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/lib/launcher.js
mediumRemote Dependency SpecdevDependencies.@flowfuse/file-server="github:FlowFuse/file-server" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.31.3-1aa3ebe-202606091427.0Review92026-06-09
2.31.2Review92026-06-09
2.31.2-e0ccb6d-202606091417.0Review92026-06-09
2.31.1Review92026-06-09
2.31.2-6e17138-202606091344.0Review92026-06-09
2.30.2-3914afb-202606041313.0Review92026-06-09
2.31.1-2108034-202606051039.0Review92026-06-05
2.31.0Review92026-06-04
2.31.1-56392b5-202606041316.0Review92026-06-04
2.30.2-23b7795-202606020920.0Review92026-06-02
2.30.2-17e1b56-202605280600.0Review92026-05-28
2.30.2-17e1b56-202605280557.0Review92026-05-28
2.30.2-17e1b56-202605271643.0Review92026-05-27
2.30.2-17e1b56-202605271253.0Review92026-05-27
2.30.2-17e1b56-202605270830.0Review92026-05-27
2.30.2-17e1b56-202605261501.0Review92026-05-26
2.30.2-17e1b56-202605261504.0Review92026-05-26
2.30.2-17e1b56-202605251142.0Review92026-05-25
2.30.2-17e1b56-202605240722.0Review382026-05-24
2.30.2-17e1b56-202605231354.0Review382026-05-24

Block this in CI

PkgRadar gates @flowfuse/nr-launcher (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @flowfuse/[email protected]