PkgRadar

npm · registry.npmjs.org

@ledgerhq/coin-tester-solana

Credential file access: matched ".aws"

Why PkgRadar flagged 1.20.0-nightly.20260527030754

SeveritySignalEvidence
highCredential file accessmatched ".aws" · package/lib-es/fixtures.js
highCredential file accessmatched ".aws" · package/src/fixtures.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
1.20.1Low risk02026-06-04
1.20.1-nightly.20260603081117Low risk02026-06-03
1.20.1-nightly.20260603030820Low risk02026-06-03
1.20.1-nightly.20260602030710Low risk02026-06-02
1.20.1-nightly.20260530030617Low risk02026-05-30
1.20.1-nightly.20260529145638Low risk02026-05-29
1.20.1-nightly.20260529151329Low risk02026-05-29
1.20.0-nightly.20260529072926Low risk02026-05-29
1.20.0-nightly.20260529030713Low risk02026-05-29
1.20.0Low risk02026-05-28
1.20.0-nightly.20260528030659Low risk02026-05-28
1.20.0-nightly.20260527030754Review352026-05-27
1.20.0-nightly.20260523030637Review352026-05-26
1.20.0-nightly.20260526030636Review352026-05-26

Block this in CI

PkgRadar gates @ledgerhq/coin-tester-solana (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @ledgerhq/[email protected]