PkgRadar

npm · registry.npmjs.org

@steedos/service-package-registry

Credential file access: matched ".npmrc"

Why PkgRadar flagged 3.0.14

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/main/default/manager/loader.js
mediumCredential file accessmatched ".npmrc" · package/main/default/manager/login.js
mediumCredential file accessmatched ".npmrc" · package/main/default/manager/npm_login.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.14Review182026-06-12
3.0.15-beta.10Review182026-06-12
3.0.15-beta.9Review182026-06-08
3.0.15-beta.8Review182026-06-05
3.0.15-beta.7Review182026-06-04
3.0.15-beta.6Review182026-06-02
3.0.15-beta.5Review182026-05-29
3.0.15-beta.4Review182026-05-27
3.0.15-beta.3Review502026-05-24
3.0.15-beta.2Review502026-05-24

Block this in CI

PkgRadar gates @steedos/service-package-registry (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @steedos/[email protected]