PkgRadar

npm · registry.npmjs.org

@socketsecurity/lib

Credential file access: matched ".npmrc"

Why PkgRadar flagged 6.0.6

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/dist/dlx/arborist.js
mediumCredential file accessmatched ".npmrc" · package/dist/dlx/package.js

Scanned versions

VersionVerdictScoreScanned (UTC)
6.0.6Review72026-06-01
6.0.4Review302026-05-28
6.0.5Review302026-05-28
6.0.3Review152026-05-27
6.0.2Review152026-05-27
6.0.0Review152026-05-25
6.0.1Review152026-05-25

Block this in CI

PkgRadar gates @socketsecurity/lib (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @socketsecurity/[email protected]