PkgRadar

npm · registry.npmjs.org

@google/gemini-cli-core

Credential file access: matched ".npmrc"

Why PkgRadar flagged 0.48.0-nightly.20260613.g9e5599c32

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/dist/src/sandbox/utils/proactivePermissions.js
mediumCredential file accessmatched ".npmrc" · package/dist/src/sandbox/utils/proactivePermissions.test.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.48.0-nightly.20260613.g9e5599c32Review152026-06-13
0.48.0-nightly.20260612.g4e10a34beReview212026-06-12
0.40.0-preview.0Review152026-06-12
0.40.0-preview.1Review152026-06-12
0.46.0Review152026-06-10
0.47.0-preview.0Review152026-06-10
0.46.0-preview.3Review212026-06-09
0.45.3Review152026-06-09
0.47.0-nightly.20260609.g0567b25a2Review152026-06-09
0.46.0-preview.2Review212026-06-05
0.45.2Review152026-06-05
0.47.0-nightly.20260605.g4196596f7Review152026-06-05
0.45.1Review152026-06-04
0.47.0-nightly.20260604.g4196596f7Review152026-06-04
0.46.0-preview.1Review152026-06-03
0.45.0Review212026-06-03
0.46.0-preview.0Review152026-06-03
0.45.0-nightly.20260602.g665228e98Review152026-06-02
0.45.0-nightly.20260530.g013914071Review152026-05-30
0.45.0-nightly.20260529.gc82e2b597Review152026-05-29
0.45.0-preview.1Review202026-05-28
0.44.1Review202026-05-28
0.45.0-nightly.20260528.g5cac7c10fReview302026-05-28
0.45.0-preview.0Review302026-05-28
0.44.0Review302026-05-28

Block this in CI

PkgRadar gates @google/gemini-cli-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @google/[email protected]