PkgRadar

npm · registry.npmjs.org

@tramvai/cli

Credential file access: matched ".npmrc"

Why PkgRadar flagged 6.81.12

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/src/utils/fixYarnSettingsOverride.ts
mediumCredential file accessmatched ".npmrc" · package/src/utils/npmRequire.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
6.81.12Review152026-06-11
7.26.8Review152026-06-10
5.53.159Review152026-06-10
7.21.1Review152026-06-10
5.53.155Review152026-06-10
6.81.11Review152026-06-10
5.53.156Review152026-06-10

Block this in CI

PkgRadar gates @tramvai/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @tramvai/[email protected]