PkgRadar

npm · registry.npmjs.org

@imolko/create-ultra-reporter

Credential file access: matched ".npmrc"

Why PkgRadar flagged 2.1.41-beta

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/bin/commands/build.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.41-betaReview102026-05-29
2.1.41Review72026-05-29
2.1.40-betaLow risk02026-05-28
2.1.40Low risk02026-05-28
2.1.39-betaLow risk02026-05-27
2.1.39Low risk02026-05-27
2.1.37-betaLow risk02026-05-26
2.1.37Low risk02026-05-26
2.1.36Low risk02026-05-25
2.1.36-betaLow risk02026-05-25

Block this in CI

PkgRadar gates @imolko/create-ultra-reporter (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @imolko/[email protected]