PkgRadar

npm · registry.npmjs.org

@nick3/copilot-api

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 1.10.34

SeveritySignalEvidence
mediumCredential file accessmatched "GITHUB_TOKEN" · package/dist/account-DpW8RaT6.js
mediumCredential file accessmatched "github_token" · package/dist/paths-Bpsb62LK.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.10.34Review62026-06-06
1.10.30Low risk02026-06-02
1.10.9Low risk02026-06-02
1.10.29Low risk02026-06-02

Block this in CI

PkgRadar gates @nick3/copilot-api (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @nick3/[email protected]