PkgRadar

npm · registry.npmjs.org

@microsoft/cpp-language-server

Credential file access: matched ".npmrc"

Why PkgRadar flagged 0.2.0

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/lib/postinstall.js
mediumNew Account With Lifecycle Hookpackage first published 56 day(s) ago, 5 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.0Review152026-06-17
0.1.0-next.2Review152026-06-17
0.1.0-next.3Review152026-06-17
0.1.0-next.5Review152026-06-17
0.2.0-next.0Review152026-06-17

Block this in CI

PkgRadar gates @microsoft/cpp-language-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @microsoft/[email protected]