PkgRadar

npm · registry.npmjs.org

@heartlandone/vega-sandbox-pr-2853-6e77df6332f70ef83eb38ce4a2811826b894a371

Credential file access: matched ".azure"

Why PkgRadar flagged 2.86.0

SeveritySignalEvidence
highCredential file accessmatched ".azure" · package/dist/esm/index-bfc6dfa2.js
highCredential file accessmatched ".azure" · package/dist/cjs/index-f054eb5d.js
highCredential file accessmatched ".azure" · package/dist/vega/p-5a25014f.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.86.0Review502026-05-25

Related campaigns

Block this in CI

PkgRadar gates @heartlandone/vega-sandbox-pr-2853-6e77df6332f70ef83eb38ce4a2811826b894a371 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @heartlandone/vega-sandbox-pr-2853-6e77df6332f70ef83eb38ce4a2811826b894a371@2.86.0
@heartlandone/vega-sandbox-pr-2853-6e77df6332f70ef83eb38ce4a2811826b894a371 — npm security scan | PkgRadar