PkgRadar

npm · registry.npmjs.org

@storm-software/linting-tools

Credential file access: matched ".npmrc"

Why PkgRadar flagged 1.133.87

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/bin/package-json-AIMJORYP.cjs
mediumCredential file accessmatched ".npmrc" · package/bin/package-json-SESRHADQ.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.133.87Review102026-06-13
1.133.86Review102026-06-13
1.133.85Review102026-06-13
1.133.84Review102026-06-11
1.133.82Review102026-06-11
1.133.81Review102026-06-11
1.133.80Review102026-06-10
1.133.79Review102026-06-10
1.133.78Review102026-06-10
1.133.77Review102026-06-10
1.133.76Review102026-06-08
1.133.75Review102026-06-08
1.133.74Review102026-06-08
1.133.73Review102026-06-08
1.133.72Review102026-06-08
1.133.71Review102026-06-08
1.133.70Review102026-06-02
1.133.69Review102026-06-02
1.133.68Review102026-06-01
1.133.67Review102026-05-30
1.133.66Review102026-05-30
1.133.65Review102026-05-30
1.133.64Review332026-05-28
1.133.62Review332026-05-27
1.133.63Review332026-05-27
1.133.59Review332026-05-25
1.133.60Review332026-05-25

Block this in CI

PkgRadar gates @storm-software/linting-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @storm-software/[email protected]