PkgRadar

npm · registry.npmjs.org

@pulumi/signalfx

Credential file access: matched ".azure"

Why PkgRadar flagged 7.28.0-alpha.1779519893

SeveritySignalEvidence
highCredential file accessmatched ".azure" · package/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
7.27.0Low risk02026-06-10
7.28.0-alpha.1781077297Low risk02026-06-10
7.28.0-alpha.1780990407Low risk02026-06-09
7.28.0-alpha.1780907516Low risk02026-06-08
7.28.0-alpha.1780904281Low risk02026-06-08
7.28.0-alpha.1780817682Low risk02026-06-07
7.28.0-alpha.1780730314Low risk02026-06-06
7.28.0-alpha.1780645218Low risk02026-06-05
7.28.0-alpha.1780558758Low risk02026-06-04
7.28.0-alpha.1780472398Low risk02026-06-03
7.28.0-alpha.1780124833Low risk02026-05-30
7.28.0-alpha.1780007328Low risk02026-05-29
7.28.0-alpha.1779953785Low risk02026-05-28
7.28.0-alpha.1779867235Low risk02026-05-27
7.28.0-alpha.1779782168Low risk02026-05-26
7.28.0-alpha.1779519893Review302026-05-25
7.28.0-alpha.1779694415Review302026-05-25

Block this in CI

PkgRadar gates @pulumi/signalfx (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @pulumi/[email protected]