PkgRadar

npm · registry.npmjs.org

@quiltdata/benchling-webhook

Credential file access: matched ".npmrc"

Why PkgRadar flagged 0.18.0

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/dist/bin/commands/publish.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.18.0Review32026-06-15
0.17.1-20260415T202609ZReview32026-06-15
0.17.1-20260415T215352ZReview32026-06-15
0.17.2Review32026-06-15
0.17.3-20260615T191957ZReview32026-06-15

Block this in CI

PkgRadar gates @quiltdata/benchling-webhook (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @quiltdata/[email protected]