PkgRadar

npm · registry.npmjs.org

@pulumi/harness

Credential file access: matched ".ssh"

Why PkgRadar flagged 0.14.0-alpha.1779693024

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/gitConnector.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.14.2Low risk02026-06-11
0.14.2-alpha.1781153335Low risk02026-06-11
0.15.0-alpha.1781075655Low risk02026-06-10
0.15.0-alpha.1780988746Low risk02026-06-09
0.15.0-alpha.1780902754Low risk02026-06-08
0.15.0-alpha.1780816151Low risk02026-06-07
0.15.0-alpha.1780728799Low risk02026-06-06
0.15.0-alpha.1780643528Low risk02026-06-05
0.14.1Low risk02026-06-05
0.14.1-alpha.1780634809Low risk02026-06-05
0.15.0-alpha.1780557199Low risk02026-06-04
0.14.0Low risk02026-06-04
0.14.0-alpha.1780548627Low risk02026-06-04
0.14.0-alpha.1780470930Low risk02026-06-03
0.14.0-alpha.1780123330Low risk02026-05-30
0.14.0-alpha.1780033837Low risk02026-05-29
0.14.0-alpha.1780007312Low risk02026-05-29
0.13.1Low risk02026-05-28
0.14.0-alpha.1779951954Low risk02026-05-28
0.14.0-alpha.1779865728Low risk02026-05-27
0.14.0-alpha.1779778744Low risk02026-05-26
0.14.0-alpha.1779693024Review1002026-05-25
0.14.0-alpha.1779518384Review1002026-05-25

Block this in CI

PkgRadar gates @pulumi/harness (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @pulumi/[email protected]