PkgRadar

npm · registry.npmjs.org

@salesforce/plugin-release-management

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 5.9.5

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/lib/repositories.js
mediumCredential file accessmatched ".npmrc" · package/lib/registry.js

Scanned versions

VersionVerdictScoreScanned (UTC)
5.9.5Review92026-06-13
5.9.4Review92026-06-13
5.9.3Review92026-06-13
5.9.2Review92026-06-06
5.9.1Review92026-06-06
5.8.32Review92026-06-03
5.9.0Review92026-06-03
5.8.31Review92026-05-30
5.8.30Review92026-05-30
5.8.29Review92026-05-30
5.8.27Review1242026-05-24
5.8.28Review1242026-05-24

Block this in CI

PkgRadar gates @salesforce/plugin-release-management (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @salesforce/[email protected]
@salesforce/plugin-release-management — npm security scan | PkgRadar