PkgRadar

npm · registry.npmjs.org

@supernovaio/cli

Credential file access: matched ".npmrc"

Why PkgRadar flagged 2.2.1

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/dist/utils/ui/services/dependency-service.js
mediumCredential file accessmatched ".npmrc" · package/dist/utils/ui/services/template-service.js
mediumCredential file accessmatched ".npmrc" · package/dist/commands/template-upload.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.2.1Review122026-06-09
2.2.4Review122026-06-09
2.2.2Review122026-05-29
2.2.3Review122026-05-29

Block this in CI

PkgRadar gates @supernovaio/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @supernovaio/[email protected]