PkgRadar

npm · registry.npmjs.org

@getpaseo/server

Credential file access: matched ".ssh"

Why PkgRadar flagged 0.1.80

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/dist/server/services/github-service.js
mediumRemote Payloadmatched "github.com/k2-fsa/sherpa-onnx/releases/download" · package/dist/server/server/speech/providers/local/sherpa/model-catalog.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.97-beta.2Low risk02026-06-17
0.1.97-beta.1Low risk02026-06-17
0.1.96Low risk02026-06-17
0.1.95Low risk02026-06-12
0.1.94Low risk02026-06-12
0.1.93Low risk02026-06-10
0.1.92Low risk02026-06-10
0.1.91Low risk02026-06-08
0.1.91-beta.2Low risk02026-06-05
0.1.91-beta.1Low risk02026-06-04
0.1.90Low risk02026-06-04
0.1.89Low risk02026-06-02
0.1.88Low risk02026-06-01
0.1.87Low risk02026-05-30
0.1.86Low risk02026-05-29
0.1.85Low risk02026-05-28
0.1.84Low risk02026-05-28
0.1.82Low risk02026-05-26
0.1.83Low risk02026-05-26
0.1.80Review422026-05-24
0.1.81Review422026-05-24

Related campaigns

Block this in CI

PkgRadar gates @getpaseo/server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @getpaseo/[email protected]