PkgRadar

npm · registry.npmjs.org

@rongcloud/imlib-next

Credential file access: matched ".AWS"

Why PkgRadar flagged 5.42.0-c-f-reaction-alpha.1

SeveritySignalEvidence
highCredential file accessmatched ".AWS" · package/index.cjs
highCredential file accessmatched ".AWS" · package/index.cjs.js
highCredential file accessmatched ".AWS" · package/index.esm.js
highCredential file accessmatched ".AWS" · package/index.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
5.30.0-enterprise.6Low risk02026-06-08
5.42.0-c-reaction-alpha.3Low risk02026-06-04
5.40.0-c-reaction-alpha.2Low risk02026-06-04
5.40.0Low risk02026-06-01
5.42.0-c-f-reaction-alpha.1Review502026-05-25
5.30.0-enterprise-alpha.16Review502026-05-25
5.40.0-alpha.4Review502026-05-25

Related campaigns

Block this in CI

PkgRadar gates @rongcloud/imlib-next (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @rongcloud/[email protected]