PkgRadar

npm · registry.npmjs.org

@jer-y/copilot-proxy

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 0.7.8

SeveritySignalEvidence
mediumCredential file accessmatched "GITHUB_TOKEN" · package/dist/main.js
mediumCredential file accessmatched "github_token" · package/dist/paths-BOztijS1.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.8Review202026-06-08
0.7.9Review322026-06-08

Block this in CI

PkgRadar gates @jer-y/copilot-proxy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @jer-y/[email protected]