PkgRadar

npm · registry.npmjs.org

@openstreetmap/id

Credential File Packaged: package/.env

Why PkgRadar flagged 2.39.5

SeveritySignalEvidence
highCredential File Packagedpackage/.env · package/.env
mediumRemote Dependency SpecdevDependencies.@actions/github-script="github:actions/github-script#v8.0.0" · package.json
mediumRemote Dependency SpecdevDependencies.editor-layer-index="github:osmlab/editor-layer-index#gh-pages" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.39.5High risk352026-06-15
2.39.6Review112026-06-15
2.40.0High risk672026-06-15
2.41.0High risk352026-06-15

Block this in CI

PkgRadar gates @openstreetmap/id (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @openstreetmap/[email protected]