PkgRadar

npm · registry.npmjs.org

@phuetz/code-buddy

Credential file access: matched ".npmrc"

Why PkgRadar flagged 0.2.0

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/dist/tools/bash.js
mediumCredential file accessmatched ".config/gcloud" · package/dist/security/sandbox.js
mediumCredential file accessmatched ".config/gcloud" · package/dist/security/sandboxed-terminal.js
mediumCredential file accessmatched ".npmrc" · package/dist/tools/bash/security-patterns.js
mediumCredential file accessmatched ".npmrc" · package/dist/workspace/workspace-isolation.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.0Review802026-06-09
0.3.0Review702026-06-09
0.4.0Review702026-06-09
1.0.0-rc.8Review852026-06-09

Block this in CI

PkgRadar gates @phuetz/code-buddy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @phuetz/[email protected]