PkgRadar

npm · registry.npmjs.org

@nanoforge-dev/actions

Credential file access: matched "GITHUB_TOKEN"

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.5Low risk02026-06-17
2.1.5-beta.73285c6Low risk02026-06-15
2.1.5-beta.799e169Low risk02026-06-14
2.1.4Low risk02026-06-11
2.1.4-beta.520fb9eLow risk02026-06-08
2.1.4-beta.fd5c580Low risk02026-06-07
2.1.3Low risk02026-06-04
2.1.2Low risk02026-06-04
2.1.3-beta.73b384bLow risk02026-06-04
2.1.1Low risk02026-06-04
2.1.1-beta.06026e4Low risk02026-06-04
2.0.1-beta.5821464Low risk02026-06-03
2.1.0Low risk02026-06-03
2.0.1-beta.35736a2Low risk02026-06-03
1.4.3-alpha.fix-release-ci.0Review352026-05-26
2.0.0Review352026-05-26
1.4.3-alpha.cannot-push-on-main.0Review302026-05-26
1.4.3-beta.97f50f4Review302026-05-26

Block this in CI

PkgRadar gates @nanoforge-dev/actions (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @nanoforge-dev/[email protected]