PkgRadar

npm · registry.npmjs.org

@socialgouv/fiches-vdd-types

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 2.1743.0

SeveritySignalEvidence
highCredential file accessmatched "GITHUB_TOKEN" · package/.github/workflows/fetch.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1763.0Low risk02026-06-12
2.1762.0Low risk02026-06-11
2.1761.0Low risk02026-06-10
2.1760.0Low risk02026-06-09
2.1759.0Low risk02026-06-08
2.1758.0Low risk02026-06-07
2.1757.0Low risk02026-06-06
2.1756.0Low risk02026-06-05
2.1755.0Low risk02026-06-04
2.1754.0Low risk02026-06-03
2.1753.0Low risk02026-06-02
2.1752.0Low risk02026-06-01
2.1751.0Low risk02026-05-31
2.1750.0Low risk02026-05-30
2.1749.0Low risk02026-05-29
2.1748.0Low risk02026-05-28
2.1747.0Low risk02026-05-28
2.1746.0Low risk02026-05-27
2.1745.0Low risk02026-05-25
2.1743.0Review302026-05-24
2.1744.0Review302026-05-24

Block this in CI

PkgRadar gates @socialgouv/fiches-vdd-types (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @socialgouv/[email protected]