PkgRadar

npm · registry.npmjs.org

@phila/cli

Credential file access: matched ".aws/"

Why PkgRadar flagged 0.7.0

SeveritySignalEvidence
mediumCredential file accessmatched ".aws/" · package/dist/commands/init.js
mediumCredential file accessmatched ".npmrc" · package/dist/utils/install-env.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.0Review72026-06-16
0.6.7Review72026-06-13
0.6.6Review72026-06-13
0.6.4Review72026-06-09
0.6.5Review72026-06-09
0.6.0Review72026-06-08
0.6.3Review72026-06-05
0.6.1Review72026-06-02
0.6.2Review72026-06-02

Block this in CI

PkgRadar gates @phila/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @phila/[email protected]