PkgRadar

npm · registry.npmjs.org

@hubspot/cms-dev-server

Credential file access: matched ".npmrc"

Why PkgRadar flagged 1.0.32

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/dist/index.js
mediumCredential file accessmatched ".npmrc" · package/dist/run.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.18.22Low risk02026-06-16
1.0.29Low risk02026-06-16
1.0.32Review102026-06-16
1.2.39Low risk02026-06-16
1.2.38Low risk02026-06-08
1.2.34Low risk02026-06-08
1.2.35Low risk02026-05-28
1.2.36Low risk02026-05-28

Block this in CI

PkgRadar gates @hubspot/cms-dev-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hubspot/[email protected]