PkgRadar

npm · registry.npmjs.org

@swayambhu-qa/core

Credential file access: matched ".azure"

Why PkgRadar flagged 0.1.35

SeveritySignalEvidence
highCredential file accessmatched ".azure" · package/dist/scripts/comment-issue.js
highCredential file accessmatched ".azure" · package/dist/scripts/create-bug.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.40Low risk02026-05-30
0.1.39Low risk02026-05-30
0.1.38Low risk02026-05-29
0.1.37Low risk02026-05-29
0.1.35Review502026-05-27
0.1.36Review502026-05-27
0.1.21Review502026-05-26
0.1.22Review502026-05-26

Block this in CI

PkgRadar gates @swayambhu-qa/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @swayambhu-qa/[email protected]