PkgRadar

npm · registry.npmjs.org

@futdevpro/nts-dynamo

Credential file access: matched "NPM_TOKEN"

Why PkgRadar flagged 1.15.34

SeveritySignalEvidence
highCredential file accessmatched "NPM_TOKEN" · package/pipeline.cicd.config.json
highCredential file accessmatched "NPM_TOKEN" · package/.github/workflows/main.yml
mediumRemote Payloadmatched "iwr " · package/package.json
mediumRemote Payloadmatched "curl " · package/.github/workflows/main.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
1.15.57Low risk02026-06-15
1.15.56Low risk02026-06-15
1.15.55Low risk02026-06-14
1.15.54Low risk02026-06-14
1.15.53Low risk02026-06-11
1.15.52Low risk02026-06-11
1.15.51Low risk02026-06-11
1.5.45Low risk02026-06-10
1.5.49Low risk02026-06-10
1.15.49Low risk02026-06-10
1.15.48Low risk02026-06-09
1.15.47Low risk02026-06-09
1.15.46Low risk02026-06-06
1.15.45Low risk02026-06-06
1.15.44Low risk02026-06-05
1.15.43Low risk02026-06-05
1.15.42Low risk02026-06-03
1.15.41Low risk02026-06-02
1.15.40Low risk02026-06-02
1.15.39Low risk02026-06-02
1.15.38Low risk02026-06-02
1.15.37Low risk02026-06-01
1.15.36Low risk02026-06-01
1.15.34Review742026-05-24
1.15.31Review742026-05-24
1.15.33Review742026-05-24

Block this in CI

PkgRadar gates @futdevpro/nts-dynamo (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @futdevpro/[email protected]