PkgRadar

npm · registry.npmjs.org

@jeffreycao/copilot-api

Credential file access: matched "github_token"

Why PkgRadar flagged 1.11.8

SeveritySignalEvidence
mediumCredential file accessmatched "github_token" · package/dist/config-DA-Jdm0G.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.11.8Review32026-06-11
1.11.6Review32026-06-11
1.11.5Review32026-06-11
1.9.0-beta.0Review92026-06-10
1.11.4Review32026-06-10
1.11.3Review32026-06-09
1.11.2Review32026-06-09
1.11.1Review32026-06-09
1.11.0Review32026-06-08
1.10.36Review32026-06-07
1.10.35Review32026-06-07
1.10.34Review32026-06-06
1.10.33Review32026-06-06
1.10.32Review32026-06-04
1.10.31Review32026-06-04
1.10.30Low risk02026-06-02
1.10.29Low risk02026-06-01
1.10.28Low risk02026-05-31
1.10.27Low risk02026-05-31
1.10.26Low risk02026-05-31
1.10.25Low risk02026-05-31
1.10.24Low risk02026-05-31
1.10.23Low risk02026-05-29
1.10.22Low risk02026-05-29
1.10.21Low risk02026-05-29
1.10.19Review72026-05-29
1.10.18Review72026-05-29
1.10.17Review72026-05-29
1.10.16Review72026-05-28
1.10.14Review72026-05-28
1.10.15Review72026-05-28
1.10.13Review72026-05-25
1.10.12Review72026-05-25

Block this in CI

PkgRadar gates @jeffreycao/copilot-api (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @jeffreycao/[email protected]