PkgRadar

npm · registry.npmjs.org

@padua/cli

Credential file access: matched ".npmrc"

Why PkgRadar flagged 3.0.0

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspreinstall added in 3.0.0 vs 2.6.0: "node scripts/check-node.cjs" · package.json
mediumCredential file accessmatched ".npmrc" · package/dist/commands/status/aws-checks.js
mediumCredential file accessmatched ".npmrc" · package/dist/commands/login/npmrc.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.3.1Review452026-06-16
3.3.0Review452026-06-11
3.2.1Review452026-06-11
3.2.0Review452026-06-11
3.1.0Review452026-06-11
3.0.0High risk1052026-06-10
2.6.0Review422026-06-02
2.5.4Review422026-06-02
2.5.2Review422026-05-29
2.5.3Review422026-05-29
2.5.0Review422026-05-28
2.5.1Review422026-05-28

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @padua/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @padua/[email protected]