PkgRadar

npm · registry.npmjs.org

@spytecgps/nova-orm

Credential file access: matched ".AWS"

Why PkgRadar flagged 1.4.243

SeveritySignalEvidence
highCredential file accessmatched ".AWS" · package/dist/utils/mysqlSpanProcessor.js
highCredential file accessmatched ".AWS" · package/dist/utils/queryTags.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.258Low risk02026-06-11
1.4.257Low risk02026-06-11
1.4.256Low risk02026-06-08
1.4.255Low risk02026-06-05
1.4.254Low risk02026-06-02
1.4.253Low risk02026-06-01
1.4.252Low risk02026-06-01
1.4.251Low risk02026-05-28
1.4.250Low risk02026-05-28
1.4.249Low risk02026-05-27
1.4.248Low risk02026-05-27
1.4.247Low risk02026-05-26
1.4.246Low risk02026-05-26
1.4.245Low risk02026-05-26
1.4.244Low risk02026-05-25
1.4.243Review502026-05-25
1.4.242Review502026-05-24
1.4.241Review502026-05-24
1.4.240Review502026-05-24

Related campaigns

Block this in CI

PkgRadar gates @spytecgps/nova-orm (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @spytecgps/[email protected]