PkgRadar

npm · registry.npmjs.org

@libp2p/mdns

Credential file access: matched ".ssh"

Why PkgRadar flagged 12.0.22-d59c165ac

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/dist/index.min.js

Scanned versions

VersionVerdictScoreScanned (UTC)
12.0.24-404c7824aLow risk02026-06-12
12.0.24-7ae12f9b0Low risk02026-06-06
12.0.24-a34745c01Low risk02026-06-05
12.0.24Low risk02026-05-31
12.0.23-160a24585Low risk02026-05-30
12.0.23-5b8813abcLow risk02026-05-30
12.0.23-b7c6dc0f2Low risk02026-05-29
12.0.23-29797a5bbLow risk02026-05-29
12.0.22-d888f182fLow risk02026-05-27
12.0.23Low risk02026-05-27
12.0.22-ed1ad1f26Low risk02026-05-25
12.0.22-d59c165acReview302026-05-25
12.0.22-3574648c3Review302026-05-25

Block this in CI

PkgRadar gates @libp2p/mdns (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @libp2p/[email protected]