PkgRadar

npm · registry.npmjs.org

@pulumi/pulumi

Credential file access: matched ".npmrc"

Why PkgRadar flagged 3.246.1-alpha.xf13388b

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/cmd/run/run.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.246.1-alpha.xf13388bReview32026-06-12
3.246.1-alpha.xbd1d2bdReview32026-06-12
3.246.1-alpha.x6120f26Review32026-06-12
3.246.1-alpha.x5c4e7eaReview32026-06-12
3.246.1-alpha.xafbf657Review32026-06-12
3.246.1-alpha.xdf58e0dReview32026-06-12
3.246.0Review32026-06-11
3.246.1-alpha.x16761b0Review32026-06-11
3.246.0-alpha.x1ff8e76Review32026-06-11
3.246.0-alpha.x2135382Review32026-06-11
3.246.0-alpha.x95e267fReview32026-06-09
3.246.0-alpha.xaa36d26Review32026-06-09
3.246.0-alpha.x1dea3edReview32026-06-08
3.246.0-alpha.x5b5cd8fReview32026-06-05
3.246.0-alpha.x439c52bReview32026-06-05
3.246.0-alpha.xa24fda4Review32026-06-05
3.246.0-alpha.xbb4f3bfReview32026-06-04
3.246.0-alpha.x92a6535Review32026-06-04
3.245.0Review32026-06-04
3.245.0-alpha.x158f072Review32026-06-03
3.245.0-alpha.xf6eec78Review32026-06-03
3.245.0-alpha.x6fea015Review32026-06-03
3.245.0-alpha.x31acb6bReview32026-06-02
3.245.0-alpha.x6f88cdfReview32026-06-01
3.245.0-alpha.xe029cfeReview32026-05-29
3.245.0-alpha.x2c17196Review32026-05-28
3.244.0Review32026-05-28
3.244.0-alpha.xa7d5f52Review62026-05-27
3.244.0-alpha.x8deae80Review62026-05-27

Block this in CI

PkgRadar gates @pulumi/pulumi (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @pulumi/[email protected]