PkgRadar

npm · registry.npmjs.org

@sisense/sdk-plugins-cli

Credential file access: matched ".npmrc"

Why PkgRadar flagged 2.26.0

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/dist/create-plugin.js
mediumCredential file accessmatched ".npmrc" · package/src/create-plugin.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
2.26.0Review202026-06-10
2.29.0Review202026-06-10
2.27.0Review252026-05-26
2.28.0Review252026-05-26

Block this in CI

PkgRadar gates @sisense/sdk-plugins-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @sisense/[email protected]