npm · registry.npmjs.org
@gem-sdk/web-components
Shipped Live Secret, Credential File Packaged, Credential file access
Why PkgRadar flagged 1.5.12
| Severity | Signal | Evidence |
|---|---|---|
| high | Shipped Live Secret | package/.env |
| medium | Credential File Packaged | package/.env |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.0.1 | Low risk | 0 | 2026-06-23 |
1.5.12 | High risk | 65 | 2026-06-23 |
1.5.4 | High risk | 65 | 2026-06-23 |
1.5.13 | High risk | 84 | 2026-06-23 |
Block this in CI
pkgradar gate --ecosystem npm @gem-sdk/[email protected]